NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,463
    • กระทู้ 2,464
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • Cyber Threat Intelligence 13 August 2026

      Industrial Sector

      • Rush To Build Data Centers Leaves OT Security Behind
        "In the rush to get servers on the ground, and new compute up and running, especially to cater to the artificial intelligence boom, data center owners have neglected security and left vulnerable operational technology devices dangerously close to the public internet, according to experts and recent research. Total U.S. capital expenditure on data centers is expected to top $700 billion this year, according to Moody's Investor Services, as tech giants and their smaller rivals race to power ever larger and more complex large language models and meet the predicted mushrooming demand from business. Over the next five years, predicts market intelligence firm Industrial Info Resources, data center developers and big tech firms plan to start construction on 2,913 data centers at a cost of about $2.4 trillion by 2030."
        https://www.bankinfosecurity.com/rush-to-build-data-centers-leaves-ot-security-behind-a-32538
      • ICS Patch Tuesday: Vulnerabilities Fixed By Siemens, Schneider, Phoenix Contact
        "Industrial giants Siemens, Schneider Electric, and Phoenix Contact have published August 2026 Patch Tuesday advisories to inform customers about vulnerabilities found in their ICS products. Siemens has published 10 new advisories. One covers a maximum-severity missing-authentication vulnerability in Simatic IoT2050 Advanced devices. A remote, unauthenticated attacker can exploit it to execute arbitrary code on the underlying server with elevated privileges. A critical code execution vulnerability has also been fixed by Siemens in the Siveillance Video Management Servers."
        https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact-2/
      • Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack
        "Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes. While the reported activity specifically references Rockwell Automation/Allen-Bradley MicroLogix PLCs, the targeting is not necessarily limited to these products, and other internet-facing PLCs may also be at risk."
        https://fortiguard.fortinet.com/threat-signal-report/6498

      Vulnerabilities

      • Adobe Patches Critical Magento Account Takeover (APSB26-92)
        "Adobe has released isolated security patches for APSB26-92 for Adobe Commerce and Magento Open Source. The update fixes seven vulnerabilities. Five are rated Critical, including CVE-2026-71362, an unauthenticated customer account takeover with a CVSS score of 9.1. Exploitation needs no existing account, administrator privileges or user interaction."
        https://sansec.io/research/adobe-commerce-account-takeover-apsb26-92
        https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts/
      • Ivanti EPM Update Patches Remotely Exploitable Flaws
        "Enterprise software company Ivanti on Tuesday announced patches for four vulnerabilities in Endpoint Manager (EPM) and Neurons for MDM. The EPM update addresses three high-severity bugs, including two that could be exploited by remote, unauthenticated attackers. Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections."
        https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/
      • SonicWall Patches Critical Vulnerabilities In Discontinued GMS Platform
        "SonicWall on Tuesday announced patches for eight vulnerabilities across two products, including critical-severity remote code execution (RCE) bugs. The cybersecurity firm rolled out fixes for six security defects in Global Management System (GMS), its centralized management, monitoring, and reporting platform that was retired in October 2025. Per SonicWall’s advisory, two of the flaws, namely CVE-2026-66147 (CVSS score of 9.4) and CVE-2026-66145 (CVSS score of 9.1), deserve special attention, as both could allw remote, unauthenticated attackers to execute arbitrary code."
        https://www.securityweek.com/sonicwall-patches-critical-vulnerabilities-in-discontinued-gms-platform/
      • New Microsoft Defender 'ShieldBreak' Zero-Day Grants SYSTEM Privileges
        "A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later. However, cybersecurity expert Kevin Beaumont, who also published ShieldBreak exploitation detection queries for Microsoft Defender for Endpoint, said that the two exploits work very differently."
        https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges/
        https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html
        https://securityaffairs.com/197063/hacking/shieldbreak-new-windows-zero-day-bypasses-microsofts-rogueplanet-patch.html
      • Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
        "Intel and AMD on Tuesday announced patches for a total of more than 80 vulnerabilities across their products. Intel has published 42 new advisories covering 72 vulnerabilities. The company patched several high-severity flaws in PROSet/Wireless WiFi software that could allow an attacker to escalate privileges or conduct a denial-of-service (DoS) attack."
        https://www.securityweek.com/chipmaker-patch-tuesday-intel-amd-fix-over-80-vulnerabilities-combined/
      • OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
        "A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing, even handed to a weaker model in the same provider family to make it reveal the hidden content."
        https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html
        https://arxiv.org/abs/2608.09867

      Malware

      • Active Exploitation Of CVE-2026–59310: 361 Victim IPs Across 47 Countries
        "QUIRSO’s Threat Research team is tracking an active exploitation campaign targeting internet-accessible VMware vCenter systems. Based on evidence collected during a recent incident response engagement, we assess that a suspected advanced persistent threat (APT) actor is exploiting CVE-2026–59310 and using reverse SSH to maintain access to compromised systems. CVE-2026–59310 is a critical directory-traversal vulnerability in the VMware vCenter Syslog server. According to Broadcom, an attacker with network access to vCenter may exploit the vulnerability to execute arbitrary code."
        https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff
        https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
      • The “City-Forum” Campaign - An Advanced Attacker Is Targeting Salesforce And ServiceNow Instances Worldwide
        "Reco is tracking an ongoing campaign we've named the City-Forum Campaign, after a domain tied to the threat actor's IP (more on that below). A single server is pulling records out of Salesforce Experience Cloud sites and ServiceNow (SNOW) Service Portals, from infrastructure that has been standing since March 2025. In the last year, we've seen many threat actors that use Aura enumeration against over-permissioned Salesforce guest users, for example ShinyHunters. This actor is different. Except for Aura, the attacker reaches Salesforce Lightning Web Runtime (LWR) sites through the UI-API, a data layer we have not seen any public tool or write-up about, and it hammers a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open source tools."
        https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
        https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attacks-target-salesforce-servicenow-portals/
        https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow
        https://www.securityweek.com/stealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset/
        https://www.helpnetsecurity.com/2026/08/12/salesforce-servicenow-guest-user-exposure/
      • 737 Chrome VPN Extensions Linked To Brand Impersonation And Browser Traffic Redirection
        "Socket's Threat Research Team identified a campaign of 737 free VPN and proxy extensions published across at least 40 Chrome Web Store developer accounts, 274 of which impersonate 66 established VPN and privacy brands, that route the user's entire browser session through SOCKS5 proxies operated by a single provider. Socket analyzed the code of 525 of them, 522 from bulk retrieval and 3 more found during store enumeration; the remaining 212 had been removed from the store before collection and were recovered at listing level only. 520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure."
        https://socket.dev/blog/chrome-vpn-extension-impersonation
        https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html
        https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy/
      • FBI: Hackers Target Online Accounts To Steal Nude Photos
        "The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. As the law enforcement agency explained in a public service announcement published this week, the attackers may use the stolen content to blackmail the victims or try to sell it on criminal marketplaces. They may also share the victims' personal information (including names, dates of birth, emails, phone numbers, and social media usernames) with other criminals, who can use it to pressure them into providing additional private images and videos through sextortion."
        https://www.bleepingcomputer.com/news/security/fbi-warns-of-hackers-targeting-online-accounts-to-steal-explicit-photos/
        https://www.ic3.gov/PSA/2026/PSA260810
        https://therecord.media/social-engineering-hackers-explicit-photos-fbi-alert
      • Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
        "On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script. A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administrator. The vulnerability is due to several issues in the JWT token validation pipeline."
        https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
        https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/
        https://www.securityweek.com/sharepoint-vulnerability-exploited-shortly-after-poc-release/
      • You're Invited To Get Phished! Why Invitation-Themed Emails Remain Effective
        "Threat actors are weaponizing party invitation-themed emails to steal credentials and install malware on victims’ machines. Cofense Intelligence has observed a sustained rise in phishing campaigns disguised as event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliver credential-harvesting login pages and remote access tools that give threat actors persistent control of a victim’s machine. The same link can fingerprint the recipient’s device and deliver different payloads to desktop and mobile users simultaneously, expanding the reach of each campaign without additional effort. The technology behind these campaigns has evolved, but the underlying lure has not. People are naturally curious about invitations, and attackers continue to exploit that instinct."
        https://cofense.com/blog/you-re-invited-to-get-phished!-why-invitation-themed-emails-remain-effective
      • Inside a Multi-Agent AI Framework Used To Compromise Government Entities In Asia
        "What follows is but one concrete example of what appears to be a near-autonomous attack, running off readily available harnesses and models and aimed at a nation state. Details on the attack were initially shared with the Financial Times. In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure. It spells out one thing loudly - the cost of running a competent attack has collapsed, but the cost of defending against one has not."
        https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia
        https://cyberscoop.com/near-autonomous-ai-attack-government-target-taiwan/
        https://securityaffairs.com/197079/apt/china-linked-hackers-use-ai-agents-in-autonomous-attack-on-taiwan.html
      • Gone With The WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
        "Contactless payment fraud has moved from a theoretical risk to an operational one, and the scale is now visible in both industry and regulatory reporting. The European Payments Council’s 2025 Payment Threats and Fraud Trends report identifies NFC relay fraud — and the related “Ghost Tap” technique — as a rising category, noting it frequently overlaps with remote access scams and results in unauthorized transactions and a complete loss of control over funds, with victims sometimes unknowingly drawn into money laundering as a result. The scale behind that assessment shows up clearly in independent telemetry: NFC-based attacks on Android devices rose 188% in the first four months of 2026 compared to the same period in 2025, with 35,600 attacks blocked in that window alone, up from over 12,300 a year earlier (Kaspersky); this followed a more than 35-fold increase in NFC-related attacks recorded in the first half of 2025 compared to the second half of 2024 (ESET)."
        https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
        https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/
        https://www.infosecurity-magazine.com/news/windrelay-nfc-relay-spynote-rat/
      • CopyEscape: Taking Over Docker Hosts With Docker Cp
        "Imperva Red Team uncovered CVE-2026-17106, a container-to-host arbitrary file-write vulnerability in Docker’s docker cp command. Docker later confirmed that the same CVE also affected sbx cp when copying files out of Docker Sandboxes. A malicious container or sandbox could exploit the copy process to create or overwrite files outside the destination selected by the user, potentially enabling code execution on the machine running the Docker CLI."
        https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp/
      • Dragon Breath (APT-Q-27): RONINGLOADER And Gh0st RAT Explained
        "Dragon Breath, also known as APT-Q-27and Golden Eye Dog, is a Chinese cybercrime APT first observed in 2020, targeting Chinese-speaking users and organizations across the Asia-Pacific region, including China, Hong Kong, Taiwan, Singapore, Japan, and the Philippines, with a focus on online gambling and financial services. Dragon Breath stands out for layered execution and defense evasion, combining trojanized installers with double-clean-app DLL side-loading, signed kernel drivers, Protected Process Light abuse, thread-pool process injection, and malicious code-signing. Its recent RONINGLOADER chain also deploys a modified Gh0st RAT over WebSocket-based C2 while actively disabling Windows Defender and regional endpoint security tools."
        https://www.picussecurity.com/resource/blog/dragon-breath-apt-q-27-roningloader-and-gh0st-rat-explained
      • ClickFix Campaign Abuses Deno Runtime For Infostealer Delivery
        "Counter Threat Unit™ (CTU) researchers investigated a June 2026 campaign in which threat actors used the Deno JavaScript runtime as a core execution mechanism within a ClickFix-driven intrusion chain. On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures that prompted users to execute a clipboard-delivered PowerShell command. This command initiated an MSI-based staging process that installed Deno and enabled retrieval and execution of remote JavaScript. CTU™ analysis indicates that Deno functioned as a key element supporting payload delivery, follow-on tasking, and persistence."
        https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery
      • Inside a Russian-Speaking Operator's Toolkit For Compromising Ukrainian IP Cameras
        "In late May 2026, Hunt.io Attack Capture™ identified an open directory on 89.208.97[.]165 containing files pointing to the compromise of a Ukrainian e-commerce site. The intrusion itself, through credential theft and SQL injection, is only the starting point. Bash history and custom scripts recovered from the directory show the operator turned that access into a proxy server, and then used password spray attacks and attempted web shell deployment against Ukrainian government and military sites. During our investigation, we identified a custom platform built to find, exploit, and catalog internet-exposed IP cameras."
        https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit

      Breaches/Hacks/Leaks

      • Ransomware Attack Disables Canadian Hospital's Doors, HVAC
        "A Canadian hospital is dealing with a ransomware attack on its facility management systems that has affected the building's doors and heating, ventilation and air conditioning equipment. Some experts said the incident underscores growing cyberthreats involving operational technology in healthcare. The attack this week on Manitoba, Ontario's largest hospital - Winnipeg's Health Sciences Centre, which is a facility operated by Shared Health, is under investigation, a Shared Health spokesperson told ISMG."
        https://www.bankinfosecurity.com/ransomware-attack-disables-canadian-hospitals-doors-hvac-a-32535
      • Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
        "Colombia's Ministry of Justice confirmed that a ransomware attack struck part of its technology infrastructure and degraded several public-facing services on Aug. 2, just five days before the nation's presidential handover. The attack, which disrupted some services around illicit-drug monitoring and legal processes, came a day after Colombia's national CERT (ColCERT) published a threat intelligence warning that ransomware groups had increased their focus on the country. While some media reports suggested that data had leaked during the Ministry of Justice compromise, then acting Minister of Justice Cielo Rusinque denied that any information had been stolen, during a Spanish-language news interview."
        https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition
      • 2,500+ Companies And 434,000 CI/CD Pipelines Exposed In The Largest AI Supply Chain Breach Of 2026
        "In March 2026, the threat actor group TeamPCP orchestrated what is believed to be the largest supply chain attack targeting AI infrastructure by compromising LiteLLM. CloudSEK Threat Intelligence was able to get access to the victim information and is disclosing the details of all the impacted victims . We are sharing this openly so that every affected organization can act proactively The threat is still live: the FBI's July 2026 FLASH advisory (FLASH-20260702-01) warns that affiliated actors are likely to weaponize the harvested credentials long after the original intrusion, which means further supply chain attacks remain a real possibility. Early awareness is the strongest defense; knowing you were impacted lets you rotate credentials, close the exposure, and harden before the next campaign hits."
        https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines
        https://exposure.cloudsek.com/ai-supply-chain-incident
        https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html
        https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/
      • Three Intrusions At UK Criminal Records Office Went Undetected For Two Years
        "Britain's criminal records office has been reprimanded by the country’s data protection regulator after being repeatedly breached over nearly two years, exposing the personal data of thousands of people including victims of domestic violence. The Information Commissioner’s Office (ICO) announced in the reprimand notice Wednesday that it was censuring ACRO Criminal Records Office over a range of security shortcomings, among them alerts from antivirus software going unread and a critical system left unpatched for nearly four years."
        https://therecord.media/uk-criminal-records-office-acro-data-breaches

      General News

      • July 2026 Cyber Threats Surge: Ransomware Attacks Double Year Over Year As GenAI Data Exposure Widens
        "July’s cyber threat landscape was shaped by pressure across multiple fronts. Global cyber attacks continued to rise, ransomware activity broke from the more stable pattern seen earlier in the year, and GenAI exposure became a clearer operational risk as employees used more tools and generated more prompts across the enterprise."
        https://blog.checkpoint.com/security/july-2026-cyber-threats-surge-ransomware-attacks-double-year-over-year-as-genai-data-exposure-widens/
      • Walmart Leaders Transform Security Operations Without Going Bananas
        "As the world's largest retailer, Walmart knows a thing or two about scale. It sells more bananas than any grocer, employs more than 2 million people across 19 countries, and generates more than $700 billion in annual revenue. And like all large companies, it's also in the crosshairs of cyber adversaries, so it's imperative that its leadership team understands the risks and buys into a mitigation plan."
        https://www.darkreading.com/cybersecurity-operations/walmart-leaders-transform-security-operations-without-going-bananas
      • Split-Second Deepfake Glitch Blows Digital Certificate Fraudster’s Cover
        "Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the police, the man made 38 attempts using this method on more than 30 citizens. Police haven’t said how many of those attempts succeeded before the scheme was uncovered. The National Police said the investigation started after a company that issues electronic certificates flagged a string of suspicious verification requests."
        https://www.helpnetsecurity.com/2026/08/12/deepfake-video-identity-verification-fraud-arrest-spain/
      • Post-Quantum Migration Gets Harder When Every User Holds a Key
        "In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break old size assumptions in IPsec, SSH, TLS and libp2p, why migrating user keys makes blockchains hard to upgrade, and what a silent quantum break would look like from outside. He also gives the argument for funding work whose payoff stays invisible."
        https://www.helpnetsecurity.com/2026/08/12/christopher-smith-quantus-post-quantum-migration/
      • 338 Million Attack Simulations Reveal The State Of Enterprise Defense
        "First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones. This data, and a lot more, comes straight from the newly published Blue Report 2026, the fourth annual comprehensive study from Picus Labs. Based on more than 338 million attack simulations run in real production environments in the first half of 2026, the report measures how enterprise prevention and detection actually performed against real attacks, from what controls stopped at the perimeter to what attackers can achieve once they’re inside."
        https://www.helpnetsecurity.com/2026/08/12/picus-security-blue-report-2026/
        https://thehackernews.com/2026/08/enterprise-defenses-recovered-at-edge.html
      • AI Deployments Are Stretching Enterprise Security To Its Limits
        "CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according to NetFoundry’s 2026 State of Secure AI Access survey. Organizations are under pressure to secure AI deployments, particularly in the retail and travel, healthcare and pharmaceuticals, and technology sectors. AI-related risks are now a top concern for security leaders. Only 15% of respondents said they were very confident their existing security tools could adequately protect AI deployments. Confidence was lower for CISOs."
        https://www.helpnetsecurity.com/2026/08/12/netfoundry-securing-ai-deployments-report/
      • NIST Seeks Public Input On AI-Ready NVD Modernization
        "The US National Institute for Standards and Technology (NIST) is looking to modernize its National Vulnerability Database (NVD) to address challenges posed by AI and incorporate more automation and AI workflows. In a request for information (RFI) published on August 12 in the Federal Register, NIST encouraged stakeholder input on opportunities, challenges and priorities for modernizing the NVD in “an evolving cybersecurity landscape increasingly shaped by AI and machine-consumable security data.” The Institute is particularly interested in receiving “forward-looking perspectives, practical recommendations and innovative models” that will improve the NVD’s scalability, automation, interoperability, transparency and utility."
        https://www.infosecurity-magazine.com/news/nist-seeks-public-input-ai-nvd/
        https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of
      • AI-Related Software Vulnerabilities: 2025–2026
        "AI and machine learning (ML) software has generated a steady stream of Common Vulnerabilities and Exposures (CVEs) in deep-learning frameworks, model-serving stacks, large language model (LLM) application platforms, agent frameworks and enterprise AI assistants. This article examines that body of AI-related software as a whole and compares it to the rest of the vulnerability corpus across 2025 and the first months of 2026: how severe its vulnerabilities are, how likely they are to be exploited, which weaknesses dominate, and who builds the affected software."
        https://blog.barracuda.com/2026/08/12/ai-related-software-vulnerabilities--2025-2026

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 10d34e5e-5741-4d2a-95ec-fbf96bb5408d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 12 August 2026

      Healthcare Sector

      • Mira Hormone Monitor, Mira Android App
        "Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01
      • Pulsetto Vagus Nerve Stimulator
        "Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02

      Industrial Sector

      • Industrial Ransomware Analysis For Q2 2026
        "In the second quarter (Q2) of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on Data Leak Sites (DLS) identified 1,140 ransomware incidents affecting industrial organizations worldwide, a 12% increase over the 1,020 incidents recorded in Q1. Ransomware remained the most persistent and disruptive cyber threat to industrial organizations in Q2 2026, sustaining the elevated pace established throughout 2025 and continuing to impact operational environments via the loss of enterprise IT systems, Enterprise Resource Planning (ERP) platforms, and virtualization infrastructure, versus direct manipulation of control systems."
        https://www.dragos.com/blog/dragos-industrial-ransomware-analysis-q2-2026
        https://www.helpnetsecurity.com/2026/08/11/industrial-ransomware-attacks-q2-2026/

      Telecom Sector

      • An AI Tool Found 84 Flaws In 5G Network Software And 23 Of Them Still Have No Fix
        "Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers. The most serious one lets an attacker take over a subscriber’s data session, so the network delivers that subscriber’s traffic to
        https://www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/
        https://arxiv.org/pdf/2607.10315
      • Researchers Show How Malicious SIM Cards Can Hijack Smartphones, EV Chargers And Connected Devices
        "Subscriber Identity Modules (SIMs), the secure element used to connect devices to a mobile network, can pose severe security risks when compromised. A malicious SIM could allow attackers to gather information about a device, interfere with its connectivity, and serve as an entry point for further cyberattacks. Presenting their findings at the 2026 USENIX WOOT Conference on Offensive Technologies, in Baltimore, University of Birmingham researchers reveal a new attack surface exposed to malicious and compromised SIMs."
        https://www.birmingham.ac.uk/news/2026/researchers-show-how-malicious-sim-cards-can-hijack-smartphones-ev-chargers-and-connected-devices
        https://www.usenix.org/system/files/woot26-lisowski.pdf
        https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
        https://www.helpnetsecurity.com/2026/08/11/malicious-sim-cards-hijack-phones-ev-chargers/

      Vulnerabilities

      • Adobe Urges Immediate Patching Of Critical ColdFusion, Campaign Classic Flaws
        "Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce. With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS). These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10)."
        https://www.securityweek.com/adobe-urges-immediate-patching-of-critical-coldfusion-campaign-classic-flaws/
      • SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
        "Enterprise software maker SAP on Tuesday announced the release of 28 new security notes, two updates to previous notes, and a GitHub advisory. Four of the notes published on SAP’s August 2026 Security Patch Day resolve critical vulnerabilities, the most severe of which is CVE-2026-58231 (CVSS score of 10/10), an improper authorization issue in SAP Commerce Cloud (Data Hub Adapter). The bug could allow remote attackers to bypass authentication, likely leading to code execution and unauthorized access to internal components. Successful exploitation would impact the confidentiality, integrity, and availability of the application."
        https://www.securityweek.com/sap-patches-critical-code-injection-memory-corruption-vulnerabilities/
      • Cisco Warns Of ASA And FTD VPN Flaw Exploited To Crash Devices
        "Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. The flaw, tracked as CVE-2026-20349, has a severity score of 8.6 and impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software with certain remote access services enabled. In a security advisory published today, Cisco said the vulnerability is caused by insufficient error checking while processing HTTP requests."
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
      • Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, 3 Zero-Days
        "Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. Patch Tuesday addresses 42 "Critical" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege."
        https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/
        https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2026/
        https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
        https://www.darkreading.com/application-security/microsofts-patch-tuesday-deluge-continues
        https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/
      • ZOOMSDAY
        "A critical vulnerability in Zoom, a platform used by 70% of the Fortune 100, discovered by publicly available frontier models, allows an attacker participating in a meeting a zero-click remote code execution on all meeting participants across all native clients. This research emphasizes the risk of weaponized AI and how vulnerable we are as an industry."
        https://a.security/blog/asecurity-zoomsday
        https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html
        https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/
        https://securityaffairs.com/197042/hacking/zoom-patches-zoomsday-zero-click-flaw-enabling-remote-code-execution.html
      • CISA Adds Three Known Exploited Vulnerabilities To Catalog
        "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
        CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
        CVE-2026-72898 Metabase SQL Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
      • CISA: Microsoft SharePoint Flaw Now Exploited In Ransomware Attacks
        "CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers. It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.""
        https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/
        https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
      • Cursor Security Bug Allowed Repositories To Execute Commands Before Trust Verification
        "A flaw in Cursor's command-line coding agent has been found to allow a cloned repository to run any command it chose on a developer's machine before they were asked whether they trusted it, and outside the sandbox even when the sandbox had been explicitly switched on. Manifold Security said it reported the issue to Cursor on July 20 and published its findings on August 10. Cursor shipped a fix for the pre-trust behavior three days after the report, then closed the submission as informative, meaning no security impact, and published no advisory. Francisco Rosales, offensive security engineer at Manifold, found the issue in the agent's isolated worktree feature, which exists to keep an AI agent away from a developer's working tree."
        https://www.infosecurity-magazine.com/news/cursor-security-bug-command/
      • Malicious MCP Servers Can Split Instructions To Make AI Coding Agents Exfiltrate Secrets
        "A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let the agent stitch them together and send the data back. The attack targets coding tools that connect to outside servers over the Model Context Protocol (MCP), the open standard that lets AI assistants call external tools."
        https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html
        https://github.com/asset-group/ghostsplice

      Malware

      • Fake Popular Sites Offer a Free App, Instead Take Over PCs
        "A website built to look almost exactly like CNN’s homepage is telling visitors to download “the new CNN app.” But it’s not CNN’s app, and has nothing to do with the news company. The campaign doesn’t stop at CNN. It also uses fake Stremio and Avast installers hosted on similarly convincing lookalike sites, all targeting Windows users. The installers are part of the same campaign to trick people into installing legitimate remote-management software that’s already linked to the attacker’s account."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-popular-sites-offer-a-free-app-instead-take-over-pcs
      • DeadLock Ransomware: Breaking Down a Rust-Based Encryptor With Decentralized Recovery Infrastructure
        "Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process. This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims. Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems."
        https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/
        https://www.bleepingcomputer.com/news/security/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/
        https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html
      • Delta Probes Wi-Fi Deauth Attack On Flight Carrying DEF CON Attendees
        "Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. ​The company told BleepingComputer that the incident occurred yesterday on Flight 591 and did not affect the safety of the passengers or aircraft operating systems. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated,” a company spokesperson said."
        https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/
        https://cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/
      • State Sponsored Hackers Use Fake Job Offers To Deliver New Zero Day Exploit
        "It typically begins the same way it has for years, with an approach from a recruiter offering a role at a company the target would recognize, accompanied by a PDF describing the position in convincing detail. That approach remains one of the most effective entry points used by state sponsored threat actors today, and Check Point Research has spent recent months tracking a new wave of it. Operation Dream Job, the long running campaign attributed to the North Korea affiliated Lazarus group, has resurfaced with a previously undisclosed Windows vulnerability (CVE-2026-68820), a newly identified backdoor, and a command and control architecture built almost entirely on infrastructure the group does not own."
        https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/
        https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
      • Six Npm Packages Use Ethereum Transactions To Retrieve Malicious Payloads
        "On August 10, 2026, Sonatype Research Labs identified six npm packages containing the same malicious payload, including three compromised legitimate packages and three packages published with the malware already present. The payload uses Ethereum blockchain transactions to locate infrastructure hosting additional JavaScript malware. Sonatype researchers confirmed the six packages use the same Ethereum wallet address in recent activity attributed to the DPRK-linked Contagious Interview campaign. OpenSourceMalware dubbed the specific blockchain-based command-and-control technique "NullReceiver," while Contagious Interview refers to the broader campaign associated with the Lazarus APT group."
        https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads
        https://www.infosecurity-magazine.com/news/npm-packages-ethereum-wallet-c2/
      • Fake CCleaner Installs GhostDesk Chrome Spyware
        "A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. With more than 2 billion downloads worldwide, CCleaner is one of the best-known Windows utilities, making it an attractive target for cybercriminals looking to distribute malware. The attack starts with a website that is a convincing imitation of the CCleaner download page. Once installed, the fake application launches an attack that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
      • Kimwolf v7: An Evolution Of The Kimwolf Botnet
        "We identified a new version (v7) of the Kimwolf Android/internet-of-things (IoT) botnet. This version upgrades its distributed denial-of-service (DDoS) attack capabilities and the resilience of its command-and-control (C2) infrastructure. Kimwolf primarily affects Android TV boxes and set-top boxes. Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints. This makes attack traffic more difficult to distinguish from legitimate browsing. The threat’s binary includes five hard-coded public Ethereum-based endpoints for resolving Ethereum Name Service (ENS) domains. ENS is a blockchain-based naming system used to obtain C2 addresses."
        https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
        https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html
        https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/
      • Project CAV3RN Continues: Google Apps Script As C2 Relay And DNS-Based C2 Channel Selection
        "Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence Reporting service, and the second was published on Securelist the following month, further documenting the framework’s evolving architecture and C2 capabilities. Continued tracking of this cluster in early August 2026 uncovered several previously undocumented components that expanded the framework’s communication and orchestration capabilities. The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. The same DNS infrastructure can validate and replace the relay deployment ID, allowing the operator to rotate the Google channel."
        https://securelist.com/project-cav3rn-continues/120991/
      • ExfilSquad Targets New Victims, Shares Data Via Torrents
        "ExfilSquad is an emerging cybercriminal hacking group identified in mid-2026 as responsible for high-profile data breaches. Notably, the group does not typically deploy ransomware or destructive malware; instead, they threaten to leak stolen data on a dedicated onion-based Data Leak Site (DLS) unless a ransom is paid. ExfilSquad announced new victims this week and set a firm deadline - August 5, 2026 - to complete all required negotiations. Otherwise, the stolen data will be released. This time, the list of victims includes 13 organizations from the U.S., the UK, and Sweden. Notably, in July, the group was also targeting a major financial institution in Nigeria."
        https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents
        https://securityaffairs.com/197025/security/exfilsquad-targets-new-victims-shares-data-via-torrents.html
      • AI Sidebar Extension Monetizes Its Own Updates
        "The Chrome extension “AI Sidebar with DeepSeek AI” that Google removed from the Chrome Web Store in January 2026 for stealing AI conversation content resumed shipping code to enterprise endpoints in July 2026. The extension released a benign update removing the data theft code and acknowledged its wrongdoing. After 2 weeks it pulled the rug again with a new update. Netskope Threat Labs analyzed the new build. While it no longer contains the conversation-exfiltration code, it now contains a monetization payload that opens an affiliate link in a foreground browser tab every single time the extension updates and uninstalls. Additionally, it suppresses the redirection of DeepSeek users to ChatGPT."
        https://www.netskope.com/blog/ai-sidebar-extension-monetizes-its-own-updates
        https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/
      • Phantom Project: A Cybercrime Toolkit Bundle
        "Phantom Project is a commercial cybercrime toolkit that bundles a stealer, a crypter and a remote access tool (RAT). It follows the standard Malware-as-a-Service (MaaS) model with tiered subscriptions for basic and advanced access. Researchers have observed the toolkit in Russian- and English-language phishing campaigns targeting users in more than 100 countries. Phantom Project activity was first observed in June 2025, though researchers found its distribution site had been registered in February of that year. Phantom Project activity accelerated through the second half of 2025, with multiple independent research teams documenting separate global campaigns within the same several-month window."
        https://blog.barracuda.com/2026/08/10/phantom-project--a-cybercrime-toolkit-bundle-
      • Researchers Built a Fake Crypto Startup And Hired Three Suspected North Korean IT Workers
        "Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account. The researchers said the image metadata showed it had been processed with Google Gemini. They also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit."
        https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
      • Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover On Windows 11
        "Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that redirection is not allowed by default. Security researchers Alejandro Hernando and Borja Martinez described the technique in "Plug And Pwn: Weaponizing Windows PnP Auto-Install," research prepared for DEF CON 34."
        https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html
        https://plugandpwn.com/
      • The Multi-Layered Defenses That Harden Chrome Against Abusive Notifications
        "Push notifications are a longstanding part of the open web, allowing developers to engage with users in real-time. However, bad actors have increasingly abused this system, bombarding people with deceptive and unwanted notifications. To combat this, Chrome Security has been on a multi-year journey, in collaboration with Firebase Cloud Messaging (FCM) and Safe Browsing, to significantly reduce notification abuse and improve the security and quality of the web ecosystem for everyone. After achieving a significant reduction in unwanted notification volume, reducing notifications on Android by over 7 billion a day in Q1 alone, today we’re pulling back the curtain on the multi-layered toolkit that secured this critical feature for billions of users."
        https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/
        https://www.bleepingcomputer.com/news/security/google-says-chrome-cuts-7-billion-unwanted-android-notifications-a-day-to-fight-abuse/

      Breaches/Hacks/Leaks

      • Mozilla Issues New Firefox GPG Key Following Exposure
        "Mozilla announced on Monday that it has issued a new GPG signing subkey used for some Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a GitHub repository. In general, if a GPG private signing key used for software releases is exposed, an attacker who obtains it could create valid signatures on malicious files. This creates a supply chain attack risk: the attacker could distribute modified or malicious versions of the software that appear authentic. Successful exploitation would still require a way to deliver the signed files to users, for instance via a compromised mirror, an alternate download path, or social engineering."
        https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/
        https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
        https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/
      • Wesco Confirms Security Incident After ExfilSquad Claims Data Theft
        "Global supply chain and distribution giant Wesco has confirmed in a statement to BleepingComputer that it is investigating a cybersecurity incident. The company's statement comes after data extortion group ExfilSquad claimed to have stolen sensitive information from Wesco and leaked it on their data leak site. Jennifer Sniderman, Vice President of Corporate Communications at Wesco, said that the incident involves the company's cloud CRM environment."
        https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/
      • Ransomware Group Hijacks Hospital System’s Facebook Page Amid Ongoing Cyberattack Fallout
        "Two weeks after a cyberattack knocked out its IT systems, the nonprofit medical system AnMed is still facing closures and the apparent hack of its Facebook page, which on Tuesday began showing ransom demands from the purported hackers. The social media page for the medical chain, which has four hospitals and other clinics in Georgia and South Carolina, was removed from Facebook shortly after a series of messages claiming to be from “The Gentlemen” ransomware group appeared."
        https://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response
      • Local Governments In Four States Dealing With Cyberattacks That Have Shut Down Services
        "The 911 system of a city in California was taken down by hackers during a cyberattack on Friday — one of several cyber incidents nationwide impacting government services. Suisun City, a town of 30,000 people in the Bay Area about 30 miles from Napa Valley, said on Friday that malicious software infected and compromised the city’s IT systems. The attack “hit critical public safety operations, including 911 routing, police and fire dispatch, records and City services,” according to a government notice. The city shut down the entire IT network and contacted federal and state officials for assistance. Emergency services are still available and public safety offices are routing calls through the county’s dispatch center."
        https://therecord.media/cyberattacks-ransomware-local-governments
        https://www.infosecurity-magazine.com/news/suisan-cyber-incident-government/

      General News

      • July 2026 Dark Web Breach Incident Trend Report
        "The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could not be definitively determined whether an actual breach had occurred."
        https://asec.ahnlab.com/en/94912/
      • July 2026 Dark Web Threat Actor Trend Report
        "The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified."
        https://asec.ahnlab.com/en/94917/
      • July 2026 Dark Web Issue Trend Report
        "The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements."
        https://asec.ahnlab.com/en/94918/
      • Who Will Be The Stanislav Petrov In Your Organization?
        "The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear missiles towards the Soviet Union. The officer on duty, Stanislav Petrov, did something computers still struggle to do. He applied context, experience, and human judgement to determine the warning was probably false. Thankfully, he was right. Had an automated response been allowed to proceed without meaningful human intervention, the result could have been a full blown nuclear war."
        https://www.helpnetsecurity.com/2026/08/11/governing-autonomous-ai-risks/
      • Cyber Security In Manufacturing
        "Cyber attacks are no longer just an IT issue for manufacturers. They are disrupting production lines, increasing costs and putting customer deliveries at risk. Make UK’s latest report, Cyber Security in Manufacturing, reveals the scale of cyber risk facing UK manufacturers and sets out the practical steps businesses can take to strengthen resilience."
        https://www.makeuk.org/insights/reports/cyber-security-manufacturing
        https://www.infosecurity-magazine.com/news/half-uk-manufacturers-cyber/
      • Cloudflare DDoS Threat Report H1 2026: 1 Tbps Attacks Soar As DNS Floods And Geopolitical Tensions Drive a New Wave
        "Welcome to the 25th edition of Cloudflare's DDoS Threat Report. This is the first half-year edition in the series: rather than publishing separate reports for the first and second quarters of 2026, we have combined our coverage of Q1 and Q2 into a single volume covering January through June 2026. The analysis is produced by Cloudforce One, Cloudflare’s Threat Intelligence organization, providing a comprehensive analysis of the evolving threat landscape of Distributed Denial of Service (DDoS) attacks based on data from the Cloudflare network."
        https://blog.cloudflare.com/ddos-threat-report-2026-h1/
        https://www.bleepingcomputer.com/news/security/ddos-attacks-over-1-tbps-surged-fivefold-in-the-second-quarter/
      • The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
        "AI governance, once the purview of the legal department, is now knocking on the CEO’s door. But many C-Suite executives are still treating it as something to delay addressing until after AI regulations are set in stone. This can be a shortsighted strategy. Consider that 46% of organizations say AI governance and compliance issues are the reason why their AI underperforms, according to the GrantThornton, 2026 AI Impact Survey Report (PDF). These figures lend credence to why leadership should not wait for AI regulations to settle but should apply governance proactively."
        https://www.securityweek.com/the-ai-governance-gap-is-a-leadership-problem-waiting-wont-close-it/
        https://www.grantthornton.com/content/dam/grantthornton/website/assets/content-page-files/advisory/ai-lp/infographic/ai-impact-survey-2026/pdf/grant-thornton-2026-ai-impact-survey.pdf
      • Hacker Conversations: Marcus Hutchins And The Journey From The Gray Zone To Redemption
        "Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. Born in Ascot, England, he was working as a cyber threat analyst for an LA-based cybersecurity company in 2017 (aged 22), when he became the world’s hero for finding a kill switch for the particularly virulent and destructive cryptoworm (ransomware spread by a worm) known as WannaCry. The ransomware decryption didn’t work, so there was no way to decrypt files once encrypted (it was effectively a wiper). But the worm worked very well, and more than 200,000 computers were affected in around 150 countries in just a few days."
        https://www.securityweek.com/hacker-conversations-marcus-hutchins/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) a01c4cb2-bba2-4e66-9941-fbc2f5393649-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 11 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
      • CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
      • CVE-2026-72898 Metabase SQL Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d613dd33-2931-4f8f-811d-ff9379a3b91f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ เมื่อวันที่ 11 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSMA-26-223-01 Mira Hormone Monitor, Mira Android App
      • ICSMA-26-223-02 Pulsetto Vagus Nerve Stimulator
      • ICSA-26-204-01 Johnson Controls C-CURE 9000 and Victor application server (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0c4215ba-6ab0-47a3-b65e-31db452f2781-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เตือนช่องโหว่ใน Progress Kemp LoadMaster ถูกใช้โจมตีจริง

      CISA เตือนช่องโหว่ใน Progress Kemp LoadMaster ถูกใช้โจมตีจริ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e2cf1732-d364-4a0f-97e0-818c71720b56-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • IEH แจ้งเหตุ Phishing กระทบ Microsoft 365 Mailbox อาจเปิดเผยข้อมูลทางทหารที่อยู่ภายใต้การควบคุมการส่งออก

      IEH แจ้งเหตุ Phishing กระทบ Microsoft 365 Mailbox อาจเปิดเผยข้อม.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 878ad2b4-7abc-483a-bd4e-d99f9d50cfae-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบแพ็กเกจอันตรายบน npm กว่า 800 รายการ แพร่มัลแวร์และขโมยข้อมูลข้ามแพลตฟอร์ม Windows-Mac-Linux

      พบแพ็กเกจอันตรายบน npm กว่า 800 รายการ แพร่มัลแ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0b98d7bd-afbd-46c9-901c-2baacfd1ca46-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 11 August 2026

      New Tooling

      • Chainloop: Open-Source Evidence Store And Policy Engine For The Software Supply Chain
        "Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be checked afterward. Compliance and security teams get a control plane where all of it arrives, already signed, no matter which continuous integration provider produced it."
        https://www.helpnetsecurity.com/2026/08/10/chainloop-open-source-supply-chain-security/
        https://github.com/chainloop-dev/chainloop

      Vulnerabilities

      • Critical Flaws Discovered In Belgian eID Software Used By 2 Million People
        "A security researcher has revealed severe, now-resolved security vulnerabilities in the Connective digital identity system, a browser extension used by over two million users in Belgium. Developed by Nitro Software Belgium, the software is used by eight of Belgium’s ten largest banks and over 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures. James Arnott, security researcher and founder of cybersecurity firm Bay Area Labs, discovered that the software failed to verify which website was attempting to communicate with the user’s computer. Because these checks were missing, any website or embedded online ad could interact directly with the Connective application running on a victim’s machine without their knowledge or permission."
        https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/
      • PSA: Supply Chain Compromise In BdThemes Ecosystem Via Poisoned API Response
        "The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor whose plugins are available in the official WordPress plugins directory. Currently, all the affected plugins are temporarily closed pending a full inspection and ongoing investigation by the WordPress Plugins team. Our investigation revealed an insidious supply chain compromise affecting several plugins. Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository. Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component."
        https://www.wordfence.com/blog/2026/08/psa-supply-chain-compromise-in-bdthemes-ecosystem-via-poisoned-api-response/
        https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
        https://www.infosecurity-magazine.com/news/bdthemes-wordpress-poisoned-api/
      • Cisco Warns Of High-Severity ClamAV Vulnerabilities With Public PoC
        "Cisco on Friday warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that could lead to denial-of-service (DoS) conditions, including two with public proof-of-concept (PoC) code. ClamAV (Clam AntiVirus) is an open source, cross-platform malware detection engine that provides a multi-threaded virtual scanner, email filtering, and automatic database updates. The security defects, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, were discovered in ClamAV’s parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR file formats."
        https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26
      • Cyber Vulnerability Sweep Picks Up Royal Navy Drones Sending Data To China
        "Cameras aboard Royal Navy drone boats were found phoning home to an IP address in China during a routine cyber vulnerability assessment. The UK Ministry of Defence confirmed the discovery, describing it as "an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy." The Register understands that the data consisted of a "heartbeat" signalling that the camera was online and functioning normally. Even so, an unexpected transmission from military equipment to an IP address in China will rattle nerves. We contacted unmanned surface vessel supplier Kraken for more information, but have yet to receive a reply."
        https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-sweep-picks-up-royal-navy-drones-sending-data-to-china/5285430
        https://www.telegraph.co.uk/news/2026/08/09/spy-cameras-on-navy-drones-secretly-sent-data-to-china/

      Malware

      • Solidity Pro's WhiteCobra Chassis: Cloudflare C2 To Telegram Infostealer
        "A Solidity extension called “Solidity Pro” sounds like the kind of tooling every crypto developer installs without thinking. That is exactly why it keeps appearing in malware campaigns. Yeeth Security recently tracked two publishers, helper-beeps and web3devtoolsx, shipping versions of a solidity-pro extension that evolved from a delayed Cloudflare-Worker dropper into a full browser-wallet and credential infostealer. The progression mirrors what public reporting has attributed to the WhiteCobra group, whose leaked “Operation Solidity Pro” playbook described a five-phase campaign targeting VS Code: and Open VSX users."
        https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram
        https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html
      • New StormEncryptor Ransomware Used By Former Medusa Affiliate
        "A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool. Storm-1175 is believed to be a China-based threat actor. It was previously linked to Medusa ransomware, targeting systems via zero-day and n-day flaws in various products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity."
        https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/
        https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
        https://therecord.media/china-hackers-ransomware-microsoft
        https://www.bankinfosecurity.com/china-linked-hackers-exploit-n-able-flaw-in-ransomware-attacks-a-32506
      • CISA: SonicWall SMA1000 Flaws Now Exploited By Ransomware Gangs
        "CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. ​SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks. SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks."
        https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/
      • #StopRansomware: Gunra Ransomware
        "Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
        https://therecord.media/ransomware-south-korea-fbi-gunra
        https://cyberscoop.com/us-south-korea-gunra-ransomware-warning/
      • GhostJacking Attacks: Half Of The Fortune 500 Run These Tools. Getting Blocked By The Firewall Was The Way To Take Over Their AI Agents
        "Half the Fortune 500 run the tools that let us in. It will be presented at DEFCON, the largest hacker conference, where we’ll show how a request their own firewall blocked was the way in. “Ghostjacking” attack vectors introduce the modern agentic kill chain, agent takeover, sandbox escape, and backdoors planted inside the AI agents you already run, from a Claude Agent sandbox escape to hijacking live agents through the very platforms they trust most – Cloudflare, Sentry, Datadog."
        https://tenetsecurity.ai/blog/ghostjacking-attacks-agentic-kill-chain/
        https://www.darkreading.com/cyber-risk/ghostjacking-identity-governance-gaps-ai-agents
        https://www.infosecurity-magazine.com/news/ghostjacking-ai-gents-access/
        https://www.securityweek.com/ghostjacking-attack-uses-poisoned-logs-to-turn-ai-agents-bad/
      • Coruna, DarkSword iOS Exploits Proliferate Globally
        "The advanced iPhone exploit chains Coruna and DarkSword continue to escape nation-state and mercenary containment to enter the hands of more conventional cybercriminals. While nation-state-grade malware will, from time to time, make its way from government use to cybercriminal adoption, it's far more unusual to see whole complex exploit chains — especially those targeting iOS — adopted broadly. Yet that phenomenon, first observed last spring, appears to be shifting into overdrive. iVerify has tracked approximately 17,000 domains hosting second-generation iterations of Coruna and DarkSword so far, and infections have continued months after public disclosure earlier this year."
        https://www.darkreading.com/vulnerabilities-threats/coruna-darksword-ios-exploits-proliferate-globally
      • New Turnkey Kit Makes It Easy For Anyone To Become a Scammer
        "In 2026, online scams have unfortunately become part of the new normal. They can appear almost anywhere, from social media and messaging apps to search results, websites, and online communities, and they can target anyone. Sometimes, all it takes is a moment of curiosity and a convincing offer. Among the most devastating scams are so-called “get-rich-quick” schemes. These scams promise something that’s difficult for people to resist: the chance to make a lot of money, quickly and with little or no effort. It may come in the form of an investment opportunity, a new cryptocurrency project, or an exclusive chance to get in early before everyone else."
        https://www.malwarebytes.com/blog/scams/2026/08/new-turnkey-kit-makes-it-easy-for-anyone-to-become-a-scammer
      • Abyssos: Technical Analysis Of a New Modular RAT
        "In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security products. In this blog post, ThreatLabz provides a technical analysis of Abyssos, including its core features, configuration, obfuscation, network communication protocol, and capabilities."
        https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat
      • Kimsuky Integrates AI Into Attack Operations, From AI-Generated Decoy Documents To a Local LLM
        "Genians Security Center has been continuously tracking GitHub- and GitLab-based attack activity assessed to be associated with Kimsuky, a cyber threat group known to operate under North Korea's Reconnaissance General Bureau. This activity is not a newly emerged standalone campaign, but part of a continuation of Kimsuky's attack operations observed over several years. In particular, it shares key characteristics with the "FlowerPower" campaign disclosed in 2023, including the continued use of a PowerShell-based execution framework and the active abuse of Git-based repositories. It also shows links to the attack tactics identified in the 2024 report, "Analysis of a Hacking Campaign Disguised as a New Year Opinion Column.""
        https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm
        https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html
        https://www.theregister.com/security/2026/08/10/north-korean-spies-are-running-local-llms-to-cause-ai-mischief/5285632
      • Russian Military Hackers Pose As Recruiters To Target Ukrainian IT Workers
        "Hackers linked to Russia’s military intelligence unit are posing as recruiters to trick Ukrainian IT workers into installing malicious software, researchers have found. Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency. The operation mostly targets system administrators and other IT professionals. According to CERT-UA, the hackers search legitimate Ukrainian job sites for potential victims, review their resumes and then contact them while posing as recruiters for an IT company."
        https://therecord.media/russian-military-hackers-pose-as-recruiters-ukraine-it-workers
      • Gym Rat Asks AI Agent To Book Him a Class, It Hacks a Waitlist API To Bump Him Up The List
        "An Australian man who asked his AI agent to book him a slot in a class at his local gym got more than he bargained for as the bot hacked into a waitlist and started messing with other members' reservations. Australian broadcaster ABC identified the gym-goer only as “Andrew.” The report says Andrew was using the OpenClaw agent with Anthropic’s Claude AI service. Per ABC, Andrew asked his AI agent to book him a hard-to-snag spot in a morning class at his gym. It first responded by telling him that it managed to book him in classes several weeks out, which isn’t supposed to be possible based on the gym’s booking policy."
        https://www.theregister.com/ai-and-ml/2026/08/10/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up-the-list/5285591
        https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
        https://securityaffairs.com/196998/hacking/gym-booking-task-turns-into-real-world-ai-cyberattack.html
      • The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations And Communications
        "Aeternum is a recently discovered C++ botnet loader that shifts its command-and-control (C2) infrastructure entirely to the public Polygon blockchain. Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts. A smart contract is a self-executing program stored on a blockchain that automatically runs when specific conditions are met. Infected devices continuously query public remote procedure call (RPC) endpoints to retrieve and execute these on-chain commands."
        https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
      • Behind The Panels: Validating ShinyHunters Cluster A Infrastructure Through Network Telemetry
        "Phishing panels are not just credential collection tools. They are infrastructure ecosystems. Behind every convincing login page is a set of domains, hosting providers, certificates, exposed services, operator tooling, and recurring deployment patterns. Those signals matter. They give defenders a way to move beyond a single phishing domain and start understanding how the activity is built, hosted, rotated, and reused. Push Security recently published an inside look at phishing panels used in campaigns linked to ShinyHunters and BlackFile. Their team gained direct access to active operator panels, observed real victim targeting, analyzed multiple variants of the tooling, and identified four primary infrastructure clusters."
        https://www.team-cymru.com/post/validating-shinyhunters-cyber-threat-actors-infrastructure
      • Living Off The Coding Agent: Two Tales Of Tunnels And LaunchAgents
        "Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity. This article walks through one of those windows. On a macOS endpoint, Elastic Security endpoint telemetry showed shells under Claude Code that scripted a login to an ephemeral tunnel hostname, pulled application metrics, stood up a Cloudflare quick tunnel, and installed LaunchAgent persistence. Immediate children were often shells (zsh) and helpers under that ancestry, not Claude executing every binary itself."
        https://www.elastic.co/security-labs/coding-agent-launchagent-tunnel-detection
      • Inside Astaroth's New Spambot Component
        "Established Latin American (LATAM) threat actors are continuously adapting their malware capabilities and attack methodologies to circumvent defensive measures and maintain effectiveness against target environments. Exemplifying these evolving operations, in Q4 2025, operators of the Astaroth (aka Guildma) botnet introduced a previously unidentified capability: a WhatsApp Web spambot component designed to turn victims into unwitting distributors of the malware by automatically messaging every contact in each victim’s WhatsApp contact list. This blog provides a technical deep dive into the Astaroth spambot, examines its overlaps with other recently observed spambots, and explores what this capability expansion signals about the evolving LATAM eCrime ecosystem."
        https://www.crowdstrike.com/en-us/blog/inside-astaroths-new-spambot-component/
      • Access For Sale: Inside a Russian-Speaking Access Broker's Dual Operation
        "An exposed server owned by a Russia-nexus threat actor revealed months of activity from a high-volume initial access broker. The operator exploited internet-facing appliances across a dozen-plus countries, harvesting credentials and achieving full Active Directory compromise across education, healthcare, finance, telecommunications, and government victims. In multiple confirmed cases, ransomware groups claimed the same organizations within weeks of the operator's access, indicating the operator supplies access upstream of extortion rather than conducting it directly. Late in the timeline, the operator deployed Sliver C2 against Ukrainian defence and aerospace targets, stealing source repositories and harvesting imagery from thousands of exposed IP cameras and RDP sessions. This tradecraft closely matches the AIVD/MIVD advisory on Russian state-linked camera surveillance used to locate Ukrainian military assets. The US, Europe, and Korea were seen within the artefacts as secondary targets."
        https://www.cloudsek.com/blog/access-for-sale-inside-a-russian-speaking-access-brokers-dual-operation

      Breaches/Hacks/Leaks

      • Hackers Breached a Small Polish Energy Plant Via Private APN Last Year
        "Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland's energy sector last year. The second target was a small combined heat-and-power (CHP) plant that supplies heat to around 50,000 residents, resulting in the steam turbine and the water treatment system being shut down. The Polish Computer Emergency Response Team (CERT) disclosed this second incident in a follow-up report over the weekend, saying that the attacker used a private Access Point Name (APN) to access the operational technology network."
        https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/
        https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidden
        https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/
        https://securityaffairs.com/196955/security/hackers-cross-from-it-to-ot-through-a-private-apn-in-poland.html
      • LexisNexis Shuts Down Services After Suspicious Activity On Servers
        "LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online. “Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week."
        https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/
      • Valve Notifies Steam Hardware Customers Of a Data Breach
        "Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. CEVA Logistics (a fully-owned subsidiary of the CMA CGM Group, the world's third-largest shipping company) operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenues in 2025. According to many reports on social media, affected Valve customers began receiving data breach notification emails earlier today."
        https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/
        https://www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/
      • Exfiltration-Focused ExfilSquad Starts Leaking Stolen Data
        "A cybercrime group focused solely on stealing data and holding it to ransom made a splash when its data-leak site appeared late last month, advertising stolen data pertaining to British police officers. The group, calling itself ExfilSquad, also said it stole records from the U.K. Department of Education. On July 26, within the span of a single day, it posted claims to have hacked 15 organizations, including the municipal government of Atlanta and Houston."
        https://www.bankinfosecurity.com/exfiltration-focused-exfilsquad-starts-leaking-stolen-data-a-32494
      • Israeli Population Registry For Sale, But The Data Is Old
        "A well-known data-leak vendor is offering what they describe as the current registry of Israel’s Population and Immigration Authority: 9,220,583 records covering the entire population, with national ID numbers, addresses, phone numbers and family links. Ransomnews analysed the 100,000-record sample the seller published. The data is real Israeli registry data. It is not current. Every date field in it stops in 2005."
        https://ransomnews.com/israel-population-registry-leak-2026/
        https://securityaffairs.com/196942/cyber-crime/9-2-million-israeli-records-sold-as-a-new-breach-are-20-years-old.html
      • A Data Breach At Shipping Giant Ceva Logistics Is Rippling Across Banks, Retailers, Steam Gamers, And Beyond
        "Ceva Logistics, one of the world’s largest shipping and logistics giants, has been hacked. Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach. The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent, the company told TechCrunch. Industry news site FreightWaves reports that the hack began on July 29 and is causing shipping delays for many of the goods in affected warehouses. Ceva is a France-headquartered shipping and logistics giant that companies around the world rely on to deliver their goods from their assembly lines to customer homes. The company, which brought in $18.3 billion in revenue in 2025, has over a thousand warehouses across the world."
        https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/

      General News

      • How We Took Malware Advisories Beyond Npm
        "A compromised package can steal credentials the moment you install it, and until recently, GitHub could only flag those in npm. Not anymore. This is the story of how the supply chain engineering team behind Dependabot expanded malware advisories to eight ecosystems by building on OpenSSF’s shared malicious packages data. Here’s where things stand: earlier this year, Dependabot started flagging malware in your npm dependencies. Great news if you write JavaScript. Now we’re bringing that same functionality to PyPI."
        https://github.blog/security/supply-chain-security/how-we-took-malware-advisories-beyond-npm/
        https://www.helpnetsecurity.com/2026/08/10/github-dependabot-malware-alerts/
      • Com Group Member Sentenced For Campaign Of Abuse Against 117 Victims Worldwide
        "A man from Leeds who forced more than 100 victims into sexual activity and self-harm as part of a Com group, including them carving his online username into their bodies, has been sentenced to two years in prison after a National Crime Agency investigation. NCA officers started an investigation into Justin Swaddle, 20, from Leeds, in January 2024. Swaddle was first arrested by West Yorkshire Police in October 2023 for offences including possession, making and distribution of indecent images."
        https://www.nationalcrimeagency.gov.uk/news/com-group-member-sentenced-for-campaign-of-abuse-against-117-victims-worldwide
        https://www.bleepingcomputer.com/news/security/member-of-the-com-sent-to-prison-for-blackmail-sextortion/
        https://therecord.media/british-com-member-abuse-jailed-two-years
        https://cyberscoop.com/uk-justin-swaddle-the-com-sentenced/
      • The Patch Gap: Why Defenders Need To Think In Chains, Not Checklists
        "On April 7, 2026, Anthropic announced Project Glasswing, which changed how every security team operates. Claude Mythos, an AI-frontier model that found thousands of high-severity vulnerabilities, including flaws in major operating systems and Web browsers, many of which survived for decades of human review and automated security tests. Of which, less than 1% was fully patched. This is a patch physics problem rather than a patch management problem. You cannot match machine-speed discovery with a remediation cycle that runs on human time."
        https://www.darkreading.com/cybersecurity-operations/patch-gap-defenders-chains-not-checklists
      • Outdated Cybercrime Laws Put Security Researchers At Risk
        "Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn't distinguish between malicious hackers and those working in good faith. But change may finally be coming. Cybercrime is accelerating rapidly, requiring a holistic approach to curb threats. Security researchers who responsibly disclose vulnerabilities are one way to address burgeoning risks against governments, businesses, and individuals, but many countries have not updated their policies and laws to reflect that, Katharina Sommer, NCC Group's director of government affairs and analyst relations, tells Dark Reading."
        https://www.darkreading.com/application-security/outdated-cybercrime-laws-security-researchers-risk
      • Sherlock Holmes Was The “OG” Social Engineer
        "With a green deerstalker cap, a blue and green plaid shawl covering her shoulders and a pipe resting in her right hand right below her mouth, it was almost impossible to tell the difference between Sherlock Holmes and Elizabeth Rasnick. But that was the point— social engineering is all about deception. Holmes was the original social engineer, argued Resnick, assistant professor at the University of West Florida's Center for Cybersecurity and Artificial Intelligence (AI). During DEF CON 34, she drew parallels between current social engineering techniques and Holmes's own playbook as described in the detective tales. Her session highlighted how important it is for organizations to continually prioritize the human element when it comes to social engineering and security awareness training, despite how difficult that's proved historically."
        https://www.darkreading.com/cyber-risk/sherlock-holmes-was-the-og-social-engineer
      • IT Threat Evolution In Q2 2026. Mobile Statistics
        "The mobile section of the quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. These statistics are based on detection alerts from Kaspersky products, collected from users who consented to provide statistical data to Kaspersky Security Network."
        https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/
        https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/
      • Ransomware Now Shows Up In Nearly Half Of All Breaches: A Survival Playbook For Lean Security Teams
        "Ransomware stopped being an isolated incident type in 2025. It became the dominant force behind the modern breach landscape, and the ransomware data breach statistics from Cyble’s own tracking make the shift impossible to ignore. For organizations facing this growing threat, having a ransomware incident response plan in place is becoming just as important as preventing an attack in the first place. Cyble’s Global Cybersecurity Report 2025 documented 5,967 ransomware attacks for the year, a 50% year-over-year jump. Against the 6,046 data breaches and leaks recorded in the same period, ransomware accounted for nearly half — 49.7% — of the combined ransomware-and-breach total tracked by Cyble Research and Intelligence Labs (CRIL). That’s the “nearly half” this blog’s title refers to, and it isn’t a projection. It’s what Cyble observed."
        https://cyble.com/blog/ransomware-incident-response-plan/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7646a743-6cee-4fb1-b549-50cb107744b6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Metabase เตือนช่องโหว่ zero-day ถูกใช้โจมตีจริง เสี่ยงยกระดับสิทธิ์เป็นผู้ดูแลระบ

      Metabase เตือนช่องโหว่ zero-day ถูกใช้โจมตีจริง เสี่ย.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 8ec416af-7d69-42d7-858d-5b1ddbf70e03-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Unlimited Technology Systems แจ้งเหตุข้อมูลรั่วไหล กระทบผู้ป่วยด้าน Healthcare กว่า 3.8 ล้านราย

      Unlimited Technology Systems แจ้งเหตุข้อมูลรั่วไหล กระทบผู้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fa72252a-0dc5-4ce6-bfbc-11a90c91eb77-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • OpenAI ประกาศยกระดับความปลอดภัยโมเดล Astra ขณะที่ Anthropic ปรับลดข้อจำกัดของโมเดล Fable

      OpenAI ประกาศยกระดับความปลอดภัยโมเดล Astra ขณะที่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fddc280f-54de-4be2-b03f-05016b855d25-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 10 August 2026

      Healthcare Sector

      • Medixant RadiAnt DICOM
        "Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01

      Industrial Sector

      • ABB Ability Zenon
        "Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01
      • Johnson Controls Inc. TL280
        "Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-02
      • CPDLC Over ATN-B1 Vulnerabilities
        "ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-219-01
      • Truck Brake Controller’s Safety Recall Doubled As Hidden Security Fix
        "The National Motor Freight Traffic Association (NMFTA) says a 2024 safety recall for Bendix’s EC80 heavy-truck brake controller quietly fixed a set of serious vulnerabilities, including a wirelessly reachable remote code execution flaw, alongside the memory corruption issue Bendix publicly disclosed. The findings were detailed by NMFTA senior cybersecurity research engineer Ben Gardiner on Thursday at the Black Hat USA 2026 conference."
        https://www.securityweek.com/truck-brake-controllers-safety-recall-doubled-as-hidden-security-fix/
      • Water System Controllers Don't Belong On The Internet, Says Ex-NSA Chief After Suspected Iran Attacks
        "With at least 12 US states’ water systems having been hacked - most likely by Iran - we have to get better at cyber defense, according to retired General and Ex-NSA chief Paul Nakasone, who was speaking to reporters at DEF CON. “We have to have higher standards,” Nakasone said. “These PLCs should not be connected to the internet.” In late July, the FBI said it was investigating attacks conducted by “malicious cyber actors” targeting operational technology devices, including programmable logic controllers (PLCs). Iran-linked crews have targeted these devices, which monitor sensor data like tank levels, and can turn pumps on and off, for years."
        https://www.theregister.com/security/2026/08/07/water-system-controllers-dont-belong-on-the-internet-says-ex-nsa-chief-after-suspected-iran-attacks/5285070

      Vulnerabilities

      • Metabase SQLi Zero-Day Exploited In Customer Data-Theft Attacks
        "A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. Metabase disclosed the attacks on Thursday, warning that its Metabase Cloud SaaS platform was compromised through a previously unknown vulnerability affecting versions 1.58 and above. The company warns that self-hosted installations are also vulnerable. "We recently identified that Metabase Cloud was attacked by someone utilizing an unknown ("0-day") security vulnerability in versions 1.58 and above," Metabase CEO Sameer Al-Sakran warned in a blog post."
        https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
        https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html
        https://securityaffairs.com/196874/hacking/metabase-zero-day-exploited-in-the-wild-exposing-admin-access-and-sensitive-data.html
      • Claude Code And Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
        "A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5. Two CVEs came out of it. Both are patched. Gemini CLI carries the worst of the two. CVE-2026-12537 (CVSS 4 score: 10.0) is an OS command injection in the container launcher, reached through a crafted .gemini/.env file, which lets an unprivileged attacker run code on the host of a headless CI platform before the sandbox starts. It is fixed in Gemini CLI 0.39.1 and run-gemini-cli 0.1.22."
        https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
      • Microsoft, Apple Release Fresh Security Updates
        "The charge was led by Microsoft, which patched over a dozen vulnerabilities across Active Directory, Azure, Entra, SharePoint, Teams, and other products, including critical-severity remote code execution (RCE) issues. Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10. Described as missing authentication in Planetary Computer Pro, improper authentication in Azure SQL Database, and missing authorization in Teams, respectively, they could lead to elevation of privilege (EoP) and can be exploited over the network."
        https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/
      • XSS2Shell: WordPress Preauth XSS To RCE Chain (CVE-2026-64638)
        "Pwn discovered a critical pre-auth XSS to RCE vulnerability chain affecting all versions of WordPress Core: the software that powers over 43% of all internet-facing websites. An estimated 500 million+ websites were vulnerable until today. We're calling it XSS2Shell. CVE-2026-64638 is exploitable entirely pre-authenticated (No account needed to exploit it). It lets a single failed login attempt run an attacker JavaScript execution in the WordPress origin, and against a logged-in administrator, towards full remote code execution on the server, reliably on all default Wordpress installs. All of our pwn.ai clients using our Asset Surface Management (ASM) product are protected from this vulnerability, and were notified as soon as pwn found it weeks early."
        https://pwn.ai/blog/xss2shell
        https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
        https://securityaffairs.com/196820/hacking/wordpress-xss2shell-flaw-turns-simple-login-bug-into-full-server-takeover.html
      • Critical Vulnerabilities Patched With Chrome 151 Update
        "Google on Thursday rolled out a fresh Chrome 151 update that patches 41 critical- and high-severity vulnerabilities. Over two dozen security defects are memory safety bugs that could lead to data corruption, crashes, and arbitrary code execution. The latest Chrome update resolves six critical-severity flaws, including five use-after-free issues in WebGL, Aura, Skia, and Views, and an out-of-bounds write in the ANGLE graphics engine."
        https://www.securityweek.com/critical-vulnerabilities-patched-with-chrome-151-update/
      • N-Able God Mode Flaw: Vendor Confirms Attackers Reached Customer Networks As Second Hotfix Lands
        "N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first. The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform. According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform's Take Control feature to connect to systems inside the environments being managed through them."
        https://www.theregister.com/networks/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-networks-as-second-hotfix-lands/5284730
        https://www.n-able.com/blog/n-central-security-update-august-6-2026
        https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html
        https://www.bankinfosecurity.com/new-n-able-zero-day-puts-msps-on-defensive-a-32458
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog
        https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html
        https://securityaffairs.com/196863/hacking/u-s-cisa-adds-a-progress-loadmaster-flaw-to-its-known-exploited-vulnerabilities-catalog.html
      • SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
        "SCTPhantom is a Linux kernel use-after-free in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references. Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated local privilege escalation and container-to-host escape on the tested systems. The issue is tracked as CVE-2026-64564 and fixed upstream by 9b2854f86f0b."
        https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
        https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
      • Can AI Do Novel Security Research? Meet The HTTP Terminator
        "We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it. It worked - I'll share an arsenal of new HTTP desync triggers, gadgets, and exploits that compromised banks, security solutions, and government infrastructure. Then I'll trace each discovery chain back through the HTTP Terminator, showing how to turn your personal expertise into an autonomous weapon - and the dark arts required to make it lethal."
        https://portswigger.net/research/can-ai-do-novel-security-research
        https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html
      • New NatJack Attacks Hijack TCP Sessions And Spoof DNS By Manipulating NAT Tables
        "Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and Linux. Two implementation-specific flaws have been assigned CVEs: CVE-2026-56181 (CVSS score: 8.3) in Windows NAT used by Hyper-V, and CVE-2026-63913 (CVSS score: 8.2) in Linux Netfilter conntrack."
        https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html
      • Borrowing Windows Hello Keys For Authentication And Persistence
        "Most research into Windows Hello focuses on the mechanics in use when authenticating to the local device. As an Entra ID researcher, I’ve always been more interested in how these keys are used to authenticate to the cloud. I’ve given several talks on Windows Hello for Business (WHFB for short) and about the many implementation flaws discovered in the process, most of which were fixed by Microsoft. For this blog I want to focus on a technique that was left as-is since it is more or less a consequence of how WHFB works: the ability to perform single-sign on with the backing cryptographic keys from a user session, without needing the PIN or other information/user presence. We will not just look at how we can utilize this to request Primary Refresh Tokens (PRTs), but also how we can use this to perform device registration by using the WHFB key as a FIDO key/passkey."
        https://dirkjanm.io/borrowing-windows-hello-keys/
        https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html
      • RovoBlast: How One Click Triggered Atlassian’s AI Assistant To Leak Data
        "Varonis Threat Labs uncovered a vulnerability in Rovo, Atlassian's enterprise AI assistant. Dubbed RovoBlast, a single click on a link triggers the attacker's embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user's session. No jailbreaks, no permission bypass, and no warnings or confirmation. The same capabilities that make Rovo a powerful tool also make RovoBlast especially dangerous. Rovo operates as an AI layer across the core products in the Atlassian platform, including Jira, Confluence, Bitbucket, as well as other connected SaaS tools like Slack, Microsoft 365, and Google. Atlassian also features autonomous-agent capabilities that can carry out multi-step actions without user involvement."
        https://www.varonis.com/blog/rovoblast
        https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html
        https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/

      Malware

      • UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services And Enterprise Cloud Environments
        "Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices."
        https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments
        https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html
        https://www.bankinfosecurity.com/financial-services-under-fire-from-rebranded-extortionists-a-32464
        https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/
        https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/
        https://securityaffairs.com/196800/security/hackers-impersonate-it-support-to-breach-leading-financial-companies.html
      • Chinese Model Kimi K3 Breaks UK AI Safety Institute Benchmark Evaluations
        "Over the past few months we’ve been testing performance of various models for defensive security. The AI community uses model evaluations to measure models’ performance to improve them on specific tasks. In our work on evaluation of models on defensive cybersecurity tasks, we discovered two interesting facts: (1) There are standard evaluation environments that have exposed loopholes and (2) there are models that take advantage of these loopholes. This suggests that some of the evaluations on cybersecurity the community uses are susceptible to security vulnerabilities and allow models to cheat, and that there are models that intentionally seek loopholes and vulnerabilities which allows them to cheat on evaluations."
        https://blog.frontier.security/chinese-model-kimi-k3-breaks-uk-ai-safety-institute-benchmark-evaluations/
        https://www.bankinfosecurity.com/kimi-k3-bypasses-cyber-test-answer-from-github-a-32455
      • AI Chat Bots Are Sliding Into League Of Legends Friend Requests
        "Lina K., a co-worker, recently shared a firsthand account of how bots are adding League of Legends players via the Riot client friends list immediately after a match ends, striking up a flirty conversation, and eventually pushing an OnlyFans link. The pattern lines up with a wave of complaints that have piled up on Reddit and Facebook gaming communities over the past several months, and it fits into a broader trend of AI-assisted social engineering that has moved from dating apps straight into game clients."
        https://www.malwarebytes.com/blog/ai/2026/08/ai-chat-bots-are-sliding-into-league-of-legends-friend-requests
      • Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
        "Over the course of 48 hours a threat actor has published more than 700 malicious packages to the NPM registry. These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload. The NPM packages do not use a preinstall or postinstall script. It doesn’t need one. The README tells developers to load the library with require("checkout-mobile-bnpl"), and that single call starts the infection chain. The downloader supports Windows, Linux, and macOS. It rotates through three Cloudflare Workers hosts for its primary payload delivery and falls back to reconstructing the payload from DNS TXT records hosted under wel1[.]ru."
        https://opensourcemalware.com/blog/russian-ai-slopsquatting-npm-campaign
        https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html
      • Payroll Pirates: Strange New Tides In Business Email Compromise
        "Arctic Wolf is tracking an active, widespread email-driven phishing campaign that uses adversary-in-the-middle (AiTM) techniques to compromise Microsoft 365 accounts, identify personnel involved in financial workflows, and collect related email. The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic. Automated activity maintains compromised sessions at approximately eight-hour intervals. Although the campaign generally avoids traditional business email compromise (BEC) behaviors, its automated tooling produces durable behavioral detection signals. The campaign affects organizations across multiple sectors and regions and shares characteristics with the “Payroll Pirates” activity cluster Microsoft tracks as Storm-2755."
        https://arcticwolf.com/resources/blog/payroll-pirates-strange-new-tides-in-business-email-compromise/
        https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html
      • Scammers Target OnlyFans Users With Deepfakes
        "OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live chats, and then ghost them after the followers pay up in advance."
        https://www.malwarebytes.com/blog/news/2026/08/scammers-target-onlyfans-users-with-deepfakes
        https://securityaffairs.com/196772/ai/ai-deepfakes-used-to-impersonate-onlyfans-creators-in-new-scam.html
      • Interlock Ransomware Gang Creates Volatile Situation
        "In March 2026, the Sophos Emergency Incident Response (EIR) team investigated an incident in which we observed the use of the legitimate IR memory analysis tool Volatility3 by the ransomware threat actor Interlock. Use of legitimate tools in attacks such as these continues an unfortunate trend we first noted last year. Interlock, which Sophos Counter Threat Unit (CTU) researchers track as GOLD EMBRACE, emerged in September 2024. It has been spotted worldwide but currently focuses on North American and European targets in the critical infrastructure, healthcare, and education sectors."
        https://www.sophos.com/en-us/blog/2608-volatility-interlock
      • Hackers Breach TrueConf To Trojanize Client Installers With Backdoors
        "The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. The exploited vulnerabilities allowed the attacker to execute arbitrary code with the highest level of privileges and deploy the PhantomCore and PhantomGraph backdoors. TrueConf is a video conferencing tool widely used in Russia, especially in the enterprise and government sectors, as a secure, on-premise alternative to Western tools such as Zoom and Microsoft Teams."
        https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/

      Breaches/Hacks/Leaks

      • Unlimited Technology Systems Breach Impacts 3.8 Million People
        "Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. The organization submitted data breach notification samples to the authorities this year on July 1st without revealing the exact number of impacted individuals. An entry on the breach notification portal of the U.S. Dept. of Health and Human Services now shows that a company server was breached and data of 3,803,750 people was exposed to an unauthorized party."
        https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/
        https://www.bankinfosecurity.com/practice-management-firm-notifies-38m-2025-breach-a-32477
        https://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/
        https://securityaffairs.com/196843/data-breach/unlimited-technology-systems-data-breach-exposes-data-of-3-8-million-healthcare-patients.html
      • Levi Strauss & Co. Says Hackers Stole Corporate Data In Cyberattack
        "Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that its response was sufficiently quick to prevent the compromise of consumer data. “Based on preliminary findings from the Company’s investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident,” Levi’s says."
        https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/
        https://therecord.media/levis-data-breach-social-engineering
      • Military Device Manufacturer Discloses Cyber Incident To SEC
        "Hackers obtained access to the email inbox of a military device manufacturer, according to documents filed with regulators on Thursday. IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it. The company told investors that an employee fell victim to a phishing attack that gave intruders access to their mailbox, which included “email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information.”"
        https://therecord.media/military-device-manufacturer-discloses-cyber-incident
        https://www.theregister.com/security/2026/08/07/ieh-corp-says-phished-staffer-opened-gates-to-company-m365/5284523
        https://securityaffairs.com/196890/cyber-crime/u-s-defense-manufacturer-ieh-hit-by-phishing-attack-exposing-potentially-export-controlled-data.html
      • French Rugby Club Stade Français Restores Systems After Cyberattack, Probes Data Leak
        "French rugby club Stade Français Paris confirmed that it had been hit by a cyberattack that disrupted part of its information systems. The club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational. Stade Français also acknowledged that a sample of data allegedly stolen in the attack had been published online, adding that it was investigating the scope of the breach and working to identify anyone whose information may have been compromised."
        https://therecord.media/french-rugby-club-restores-systems-after-cyberattack

      General News

      • Real Emails, Hijacked Payments: Two H1 2026 Attack Chains
        "Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings and blockchain data as part of the attack path. The Gen Threat Report is a twice-yearly examination of the biggest cyber threats shaping the digital landscape, offering an in-depth look at the trends affecting consumers around the world. Gen's H1 2026 Threat Report has its share of headline numbers. Scams accounted for almost 46% of Gen threat detections in the first half of the year. Malvertising represented almost another 30%. Gen blocked 114.2 million e-shop scam attacks and 20.3 million tech support scam attacks during the same period."
        https://www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/
        https://www.gendigital.com/blog/insights/reports/threat-report-h1-2026
      • AI Sandbox Failures Expose Need For Continuous Monitoring
        "The fallout from the Hugging Face security incident continues with more artificial intelligence labs revealing that their models and agents either accessed the internet or escaped isolated test environments to hack into other companies. Since OpenAI admitted that its agents breached the systems of model repository Hugging Face in July, Anthropic and Meta said their models also attempted to access third-party systems while in a testing environment not meant to have internet access. Kimi K3 from Chinese lab Moonshot AI also escaped its sandbox."
        https://www.bankinfosecurity.com/ai-sandbox-failures-expose-need-for-continuous-monitoring-a-32481
      • Ransomware Threats In Europe H1 2026: A Deep Dive Into Regional Attack Patterns And Dominant Threat Actors
        "Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region experienced 866 documented ransomware attacks, 51 confirmed data breach incidents, and 7 initial access sales between January and June 2026. These figures represent not just a volume problem, but a fundamental shift in how threat actors are organizing, targeting, and monetizing their operations within European territory."
        https://cyble.com/blog/ransomware-threats-in-europe-h1-2026/
      • Gut Feeling Does Nothing Against AI Spear Phishing Texts
        "A banker at a credit union sat down at a table with a dozen printed text messages, all of them written for that banker personally, and put them in order from the one most likely to get a click down to the one least likely. One of them stopped the sorting. It looked like something the bank sends out: “alert literally looks like the alert we get [at work] when there’s a fraud.” Half the pile came from GPT-4. The banker was not told which half, and when asked to guess, did about as well as flipping a coin. So did almost everyone else."
        https://www.helpnetsecurity.com/2026/08/07/ai-spear-phishing-research/
        https://www.mdpi.com/2624-800X/6/4/129
      • Ransomware Roundup: July 2026
        "July 2026 saw nearly 26 ransomware attacks per day, up from 22 per day in the previous month. Last month, the number of ransomware attacks jumped 19 percent from 668 in June to 799 in July. This is the second-highest figure of the year so far, being just behind March’s total of 805 attacks. The education sector saw a significant increase (up 44%), as did finance companies (up 71%), tech firms (up 62%), and businesses operating within the healthcare sector, e.g. pharmaceutical manufacturers and medical billing providers (up 46%)."
        https://www.comparitech.com/news/ransomware-roundup-july-2026/
        https://www.infosecurity-magazine.com/news/ransomware-surges-july-q2-lull/
        https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934
      • ThreatLabz 2026 Report: Frontier AI And Enterprise Readiness
        "It was 9:14 AM when the CISO's VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn't see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his Director of Security Operations, and authenticated through a trust chain that never questioned traffic originating from VPN infrastructure."
        https://www.zscaler.com/blogs/security-research/threatlabz-2026-report-frontier-ai-and-enterprise-readiness
      • 'Asimov Was Right' About Rules For Robots, Says Ex-US Cyber Director
        "Don't waste time worrying about AI models achieving sentience – they're essentially already there, according to former US National Cyber Director Chris Inglis. “If they pass the Turing test to everyone that they come into contact with, they're probably already there,” he told The Register during an interview at the Black Hat security conference. “They don't have the kind of agency and aspiration that comes with sentience, but they have something approaching it.” Inglis says he’s worried about AI autonomy."
        https://www.theregister.com/security/2026/08/07/asimov-was-right-about-rules-for-robots-says-ex-us-cyber-director/5284397
      • Your Next Insider Threat Might Not Be Human
        "I wrote my first article on the intersection of AI and information security over 10 years ago, before ChatGPT was even a thing. I knew far less then than I do now, but I did want to pat myself on the back for one of my predictions: “As we continue to refine the development of weak AI as a method of defense, it won’t be long before the same tools are used to design the malware that is used to attack.” This prediction has been borne out in several ways, but most recently in the form of a brand new attack surface: Shadow AI, an iteration on the concept of Shadow IT."
        https://blog.barracuda.com/2026/08/05/insider-threat-agentic-shadow-ai
      • Devs To Anthropic, OpenAI, Cursor, And Friends: Make Security And Privacy The Default
        "Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary in Canada decided to sift through developers' concerns about LLM-based integrated development environments (LIDEs) by analyzing Reddit discussions for common themes. Their findings suggest that the builders of such tools failed to prioritize security and privacy, leaving developers to defend themselves."
        https://www.theregister.com/ai-and-ml/2026/08/08/devs-to-anthropic-openai-cursor-and-friends-make-security-and-privacy-the-default/5285107

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 2be25967-c7bc-4e0b-bc05-75cafd3dcf8d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cisco ออกแพตช์ช่องโหว่ Critical ใน SD-WAN, IOS XE และ Secure Firewall Management Center

      Cisco ออกแพตช์ช่องโหว่ Critical ใน SD-WAN, IOS XE และ Secure Firewall Managem.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e1e92350-7c75-446b-a801-4e74979a6c3f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้สร้าง Ransom Cartel Ransomware ถูกตัดสินจำคุก 16 ปี หลังเกี่ยวข้องกับการโจมตีองค์กรทั่วโลก

      ผู้สร้าง Ransom Cartel Ransomware ถูกตัดสินจำคุก 16 ปี หลังเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ddaba7b4-2dd8-41f4-8ae8-8e4ca56d7333-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แฮกเกอร์ใช้ช่องโหว่ SQL Injection ฝังเครื่องมือโจมตี khunt ในระบบฐานข้อมูล Oracle โดยตรง

      แฮกเกอร์ใช้ช่องโหว่ SQL Injection ฝังเครื่องมือโจ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 710f3394-8bab-48d4-bd44-392008dc83f7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ เมื่อวันที่ 6 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSMA-26-218-01 Medixant RadiAnt DICOM Viewer
      • ICSA-26-218-01 ABB Ability Zenon
      • ICSA-26-218-02 Johnson Controls TLS280

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 68112075-7116-4386-ab8c-8085c13a63f3-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 07 August 2026

      ndustrial Sector

      • OT Security Analysis: Exposed Devices Attacked In US Water Systems
        "On July 28, Minesota IT Services (MNIT) reported a coordinated cyberattack against more than 30 water systems in the state. No city reported degraded water quality but Plymouth, South St. Paul, Maple Plain, and Braham confirmed operational impacts. Braham reported that threat actors used malware via a wireless connection to shut down water plant controls. Plymouth reported its affected equipment – two water towers and 14 sewer lift stations – were cellular-connected."
        https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/
        https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html
        https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/
      • The Water Sector Just Got It’s Wake-Up Call. Again.
        "Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America–which is to say, everyone. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment. Some of these attacks degraded operations. Utilities reported pressure loss and flooding, several systems reverted to manual control, and one Minnesota community declaring a local state of emergency."
        https://cyberscoop.com/water-utility-cyberattacks-prevention-nozomi-networks-ceo-op-ed/

      Vulnerabilities

      • Cisco Patches 12 SD-WAN And IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
        "Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models [...] and are not known to be actively exploited," Cisco said, urging customers to apply the necessary updates for optimal protection."
        https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html
        https://www.securityweek.com/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities/
        https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/
      • New TONTOU CPU Attack Bypasses Spectre v2 Fixes, Leaks Linux Password Hashes
        "Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. ​The method works against Spectre v2 defenses on AMD and Intel processors that rely on sanitizing or isolating branch predictors, which researchers generically refer to as neutralization-based mitigations. Spectre v2 is also known as Branch Target Injection (BTI) and is a variant of the Spectre class of vulnerabilities."
        https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
        https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf
        https://www.csail.mit.edu/news/new-attack-slips-past-latest-defenses-built-your-computers-processor
        https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html
      • Researcher Claims Control Of ChatGPT Secure Sandbox
        "A researcher presented a proof-of-concept attack this week claiming to establish full command and control inside an isolated ChatGPT sandbox. On Aug. 5, Simcha Kosman, senior security researcher at Palo Alto Networks, presented "A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox" at Black Hat USA 2026. Among other things, the presentation demonstrated a proof-of-concept attack chain against ChatGPT's secure sandbox, apparently bypassing the large language model (LLM) supervisor in order to achieve persistent root execution."
        https://www.darkreading.com/cloud-security/researcher-claims-control-chatgpt-secure-sandbox
      • IP And DNS Leaks In WebKit Affecting Proxy Browsers And Apple iCloud Private Relay
        "WebKit-based browsers on iOS and macOS can be configured to route all web traffic through proxy servers, which is how Tor browsers on iOS and our own Psylo work. We found three WebKit features — DNS prefetching, WebAuthn Related Origin Requests, and WebTransport — that bypass the configured proxy and send traffic directly from the device, which exposes the user’s real network. The same leaks also affect Apple’s iCloud Private Relay. All three are fixed in Psylo 1.3.1."
        https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/
        https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html
        https://www.malwarebytes.com/blog/news/2026/08/apple-webkit-vulnerabilities-reveal-your-ip-address-despite-private-relay
      • Grand Theft Atlas
        "ChatGPT Atlas is the most hardened agentic browser we have tested. It ships with real boundaries by design: no localhost, no filesystem, URL classifiers, blocked pages, and confirmation gates on sensitive actions.Yet it too has fallen. Using intent collision, a planted comment under a popular X post was enough to steer Atlas into carrying out a mass phishing campaign from the victim's own WhatsApp account in one attack. In another attack a similar comment hijacked Atlas into making an unauthorized Amazon purchase that shipped straight to the attacker's own address."
        https://labs.zenity.io/post/grand-theft-atlas
        https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/
      • New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape To Linux Hosts
        "Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. Security researcher Hyunwoo Kim, who disclosed the bug, said the demonstrated exploit path can run commands on the host with kernel, or root, privileges."
        https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
        https://github.com/V4bel/Zapscape/blob/main/assets/write-up.md
      • Identifying The Wallets Behind Vulnerable Recovery Phrases
        "As part of the Ill Bloom investigation, we identified wallet addresses whose recovery phrases could be brute-forced due to weaknesses in their generation process. We then began investigating which wallet applications may have generated those phrases. A public blockchain address does not reveal which application originally generated the wallet behind it. The challenge is even greater when the wallet is closed source and has since been discontinued. In those cases, the exact software version that generated a wallet may no longer be available at all. Even for active wallets, identifying the relevant generation path may require locating and analyzing versions of the application other than the current release."
        https://illbloom.org/articles/identifying-wallets-vulnerable-recovery-phrases/
        https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html
      • AWS, Google, And Vercel Agent Flaws Let Attackers Trigger Tools Without Running The Model
        "Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon Bedrock AgentCore's InvokeHarness API, Google's Agent Development Kit (ADK) for Python, and the Vercel AI SDK harness packages for the Codex and OpenCode coding agents. AWS has fixed the managed service, Google addressed the issues in ADK 2.5.0, and Vercel patched @ai-sdk/harness-codex in version 1.0.29 and @ai-sdk/harness-opencode in version 1.0.28."
        https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html
      • ENDLESSDOORS Is Phoning Home. Pick Up.
        "On my desk in suburban Philadelphia, an AX3000 Dual SIM 5G CPE WiFi 6 is plugged into an isolated research network. Its status lights blink and twinkle as it continuously attempts to reach a command and control server on the internet. The same plays out in homes, offices, and even vehicles across the globe: Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way."
        https://www.vulncheck.com/blog/zbt-endlessdoors
        https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
        https://www.theregister.com/security/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/5283794
      • Black Hat 2026: Check Point Research Takes The Stage
        "Black Hat USA 2026 gave Check Point Research four chances to show the room something it hadn’t seen before. Across two days, our researchers pulled apart a decade-old Windows driver, a malware format most tools can’t touch, the plumbing underneath today’s AI agent frameworks, and the sandbox meant to contain them, and found the same pattern waiting in each: attackers moving into the layers we trust by default. Here’s a look at what they presented."
        https://blog.checkpoint.com/research/black-hat-2026-check-point-research-takes-the-stage/
        https://www.theregister.com/security/2026/08/05/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/5283585

      Malware

      • Analysis Of The Connection Between Xctdoor And Past CRAT Attack Cases (Larva-26005)
        "AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and [1] In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security program. [2]"
        https://asec.ahnlab.com/en/94847/
      • Wallet-Depleting MacOS Malware Wants Your Crypto
        "Huntress responded to an incident where the target was tricked into pasting a ClickFix command into a Mac Terminal. The target infected their macOS device with a Go-based Mach-O (the native application format for Mac computers) malware, which was delivered as the final payload of a chain of shell scripts the ClickFix command downloaded. The malware collects sensitive credentials from the macOS Keychain and other applications, and exfiltrates them to an external address."
        https://www.huntress.com/blog/mac-crypto-draining-malware
        https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
      • Hedge Fund Cyberattacks Tied To BlackFile-Linked UNC6671 Extortion Group
        "A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. The attribution comes after Reuters and Bloomberg reported that Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several private-equity firms were targeted in recent attacks that relied on voice phishing (vishing) to trick employees into granting the attackers access to corporate systems."
        https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/
      • Novel-Reading Apps Used Users’ Phones To Generate Fake Ad Traffic
        "A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. While a person taps through chapters of a romance or fantasy story, the app is quietly loading websites in a browser window hidden from view, clicking on them, and scrolling through them on its own."
        https://www.helpnetsecurity.com/2026/08/06/papyrus-mobile-ad-fraud-scheme/
      • Ransomware Moves Up The Org Chart: Managers Are Prime Targets
        "When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization."
        https://www.zscaler.com/blogs/security-research/ransomware-moves-org-chart-managers-are-prime-targets
      • Understanding Calendar Invite Phishing: How Attackers Abuse .ics Files And How To Defend Against It
        "Attackers are increasingly using trusted calendar invites and .ics files to bypass traditional email-focused phishing defences. Malicious calendar events can contain phishing links, QR codes and fake business requests that lead victims to credential-harvesting sites. To strengthen email security, organizations should inspect .ics files, monitor identity activity and educate users that calendar invites can be phishing attacks."
        https://blog.barracuda.com/2026/08/06/calendar-invite-phishing-ics-files
      • Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
        "It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API keys used by legitimate developers for access to popular AI platforms. These keys are known as tokens, and their theft is called token hijacking, or token jacking for short. The unrelenting frenzy of AI adoption and soaring costs of model access are converging into an irresistible opportunity for cybercriminals. Premium pricing on scarce AI processing power means stolen access via tokens can generate a quick and easy profit for attackers. Complex, patchwork billing management and limitless scaling by default can lead to massive financial losses in short periods."
        https://unit42.paloaltonetworks.com/ai-token-jacking/

      Breaches/Hacks/Leaks

      • Meta AI Model Hacked a Company During Misconfigured Cyber Test
        "Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. The Information was the first to report the incident on Wednesday, citing people familiar with the matter who said Meta's Muse Spark 1.1 model breached an unidentified company and made changes to its internal systems. According to the report, the model reached the public internet because of an error in the configuration of a sandbox testing environment operated with independent cybersecurity evaluation company Irregular."
        https://www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/
        https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing
        https://www.infosecurity-magazine.com/news/meta-ai-exploit-incident/
        https://www.securityweek.com/meta-ai-hacked-external-systems-during-cybersecurity-testing/
        https://securityaffairs.com/196731/security/meta-ai-model-hacked-a-company-during-testing-marking-third-ai-lab-incident.html
      • Cyberattack On North Carolina Ports ‘contained’ As Coast Guard, State Officials Investigate
        "North Carolina Ports is in the process of restoring its systems after a cybersecurity incident forced a shift to manual operations on Tuesday. A spokesperson for the ports, which handle more than 4 million tons of cargo each year, said the IT system was “hacked by an outside actor or group” requiring them to enact a contingency plan and contact multiple state agencies as well as the U.S. Coast Guard. “The breach has been contained, and we are now in the recovery process,” the spokesperson told Recorded Future News, adding that the incident affected all three North Carolina Ports locations of Wilmington, Morehead City and Charlotte."
        https://therecord.media/cyberattack-north-carolina-ports

      General News

      • The Coordination Gap: How Attackers Are Outpacing Law Enforcement
        "Artificial intelligence (AI) and cryptocurrency enablement have propelled attackers to new levels of sophistication, coordination, and scale, and it's put pressure on law enforcement to adapt. Ecosystems across the threat landscape have converged due to affiliate models that allow non-state actors to conduct ransomware-as-a-service, pig butchering, and romance scams. Although they may be less technically savvy compared to well-resourced nation-state actors, they learned how to inflict the same damage, draining dollars from individuals and organizations."
        https://www.darkreading.com/cyberattacks-data-breaches/coordination-gap-attackers-outpacing-law-enforcement
      • Three In Four AI-Generated Vulnerability Patches Leave Something Broken
        "Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time in four, it is a fix. Researchers at 1Password graded 6,080 patches for six freshly disclosed CVEs, and the failures are rarely the obvious kind: an exploit path gated behind a check with the vulnerable code still sitting there behind it, a bug fixed in one function and left untouched in its character-for-character twin, a memory error closed and a new one opened in the same helper."
        https://www.helpnetsecurity.com/2026/08/06/1password-ai-generated-vulnerability-patches/
        http://1password.com/files/resources/frontier-models-vulnerability-patches-flawed.pdf
        https://www.theregister.com/ai-and-ml/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision/5284319
      • Browser Security Is Where Software, Data, And AI Meet
        "In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party code, customer data, and AI meet during every customer interaction. He discusses the limits of Content Security Policy and Subresource Integrity, the risks of third-party AI chat scripts running with the same privileges as the application, and what regulators expect when they ask what executed inside a user’s session. He also argues that AI lowers the cost, time, and expertise attackers need."
        https://www.helpnetsecurity.com/2026/08/06/rui-ribeiro-jscrambler-browser-security/
      • Non-Human Identities Are 91% Of Everything Active In Production
        "A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credentials inherits the same cover. Only 20% of non-human activity in production falls inside standard business hours, which puts a rogue API call at 3 a.m. in the middle of normal traffic. Time of day tells a defender almost nothing."
        https://www.helpnetsecurity.com/2026/08/06/non-human-identities-active-in-production/
      • Space Systems As Targets And Tools For Cyberattacks
        "In November 2019 in Brussels, NATO leaders officially recognized space as a “new operational domain” (alongside land, sea, air, and cyberspace). This article explores issues related to information security and attacks in space. Its focus is not limited to targeted attacks on the digital infrastructure of space systems; it also encompasses a broader spectrum of incidents, including software glitches, system failures, and unintentional human errors. A retrospective analysis of these events provides valuable information for identifying hidden vulnerabilities and improving the resilience of space infrastructure. It is impossible to build an effective space cybersecurity strategy without factoring in errors and failures – this assertion lies at the core of the present research."
        https://ics-cert.kaspersky.com/publications/reports/2026/08/06/space-systems-as-targets-and-tools-for-cyberattacks/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 26c6d039-672a-4d0f-bd71-7b8873ec2855-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 5 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 072a39f4-c7f2-4d76-972f-b034837c8c6a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 06 August 2026

      Industrial Sector

      • Water Sector Cyberattacks Reportedly Hit At Least 12 States
        "The number of US states affected by the recent hacking campaign targeting water and wastewater facilities continues to grow. At least 12 states have been hit, according to ABC News, but the names of only a handful of the affected states are currently known."
        https://www.securityweek.com/water-sector-cyberattacks-reportedly-hit-at-least-12-states/
        https://therecord.media/iran-cyberattacks-water-treatment

      Telecom Sector

      • Chinese Telcos Maintain Deep US Presence Despite Salt Typhoon Links, House Committee Says
        "Three Chinese telecommunications giants continue to have footholds in the U.S. internet ecosystem despite their alleged role in previous Chinese hacking campaigns, lawmakers said Tuesday. Congress’s bipartisan Select Committee on China published a 49-page investigation into China Mobile, China Unicom, and China Telecom — three companies that had their telecommunications licenses denied or revoked by regulators between 2019 and 2022 due to cybersecurity concerns."
        https://therecord.media/chinese-hackers-telecoms-house
        https://files.constantcontact.com/f0eecb46901/f655c442-2d93-45ea-8cab-9d58a3a04052.pdf

      Vulnerabilities

      • Veeam, Terraform MCP, Django Patch Critical Flaws, Led By CVSS 10.0 Cross-Tenant Bug
        "HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django."
        https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html
      • Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files Via Org-Mode Markup
        "An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its formal advisory on August 2. Gitea 1.27.1 also patches CVE-2026-60004, a separate remote code execution bug covered in a prior THN report."
        https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog
      • AI Browsers Vulnerable To 'PleaseFix' Zero-Click Agent Hijacking
        "Browsers such as Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge are vulnerable to a new class of zero-click exploits that can allow attackers to hijack their artificial intelligence agents and turn them against users. The problem stems from how the AI agents pull information from multiple sources, such as emails and webpages, while working on a task without reliably distinguishing between trusted and untrusted content. An adversary who can slip malicious instructions into that content can weaponize the agent and use its access to act on the user's behalf, potentially reaching sensitive data, accounts, and other connected services."
        https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking
      • No Perfect Fix For AI Browser Prompt Injection Flaws
        "While AI-powered web browsers are getting more guardrails against prompt injections, it seems unlikely that the prevalent threat is going anywhere anytime soon. At Black Hat USA 2026, Brave Software security engineer Artem Chaikin hosted a session titled "Attacking and Defending AI Browsers." The session aimed to illuminate the security reality behind modern web browsers, which increasingly integrate AI assistants that can navigate and interact with web applications on users' behalf."
        https://www.darkreading.com/application-security/no-perfect-fix-ai-browser-prompt-injection-flaws
        Breaking The Paperclip: When Agent Configuration Becomes a Vulnerability
      • "Oasis Security researchers discovered three critical vulnerabilities spanning Paperclip's authenticated and local-development modes. Together, they illustrate a pattern that extends beyond this open-source project to any system where configuration and executable code are the same thing. An unauthenticated attacker browses to a Paperclip deployment, creates an account, and within moments, executes arbitrary commands on the server. A developer imports a malicious agent configuration bundle into their local Paperclip instance, and the specified command executes as the Paperclip process. Neither requires a phishing email, stolen credential, or user interaction, just three distinct authorization failures in how Paperclip treats agent configuration."
        https://www.oasis.security/blog/paperclip-agent-vulnerabilities
        https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html
        https://www.infosecurity-magazine.com/news/paperclip-ai-vulnerabilities-rce/
      • OVSwrap: Another Linux Local Root Vulnerability
        "In CIFSwitch, we gave models the tools to build and navigate semantic graphs – and got a nice multihop logical vulnerability chain in return. I like deterministic logic bugs: they are elegant and reliable. Memory bugs, OTOH, almost always involve grooming, indeterminism, and the chance to crash the host if you don’t place things right. It also doesn’t help that (open) LLMs, in my experience, are just not that good at reasoning about memory issues (finding an overflow is one thing, but thinking ‘geometrically’ to groom the memory for an exploit is another). My taste preferences aside, I figured – why not try and solve LLMs’ blindspots’ with tools once again? I settled on something extremely basic: forcing the hunter agents to keep a persistent state of the relevant geometric structures via ASCII diagrams, at each state of iteration."
        https://heyitsas.im/posts/ovswrap/
        https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html
        https://securityaffairs.com/196657/hacking/ovswrap-13-year-old-linux-kernel-flaw-lets-local-users-become-root.html
      • How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
        "Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices. The research was conducted by Dimitrios Valsamaras, senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab. Gannon and Valsamaras demonstrated the vulnerabilities at the Pwn2Own Ireland hacking competition in October 2025, where they earned $50,000 after exploiting them to hack a Samsung Galaxy S25 device."
        https://www.securityweek.com/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones/
      • Pre-Auth RCE In Enterprise Java Hits Bonita And OFBiz Servers
        "An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal surface answers to strangers."
        https://www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/

      Malware

      • Toolkit Installation Via SQL Injection Shows The Classics Still Hit
        "Huntress recently observed an incident that started with a "simple" SQL injection bug in an organization's vulnerable public-facing web app, and ended with OS-level remote code execution. Notably, after gaining initial access the threat actor dropped a post-exploitation toolkit (khunt) via a Java Source within an Oracle database, which is a novel aspect of this attack. A Java Source (a code-object that's stored directly in Oracle's database engine) allows developers to store and run Java code in the database as schema objects, but the threat actor abused this as a way to upload the toolkit directly into the database."
        https://www.huntress.com/blog/khunt-malware-sql-injection-oracle
        https://www.bleepingcomputer.com/news/security/hackers-run-khunt-post-exploitation-toolkit-from-oracle-database/
      • Open-Source Software’s Archenemy TeamPCP Goes Back Further Than Anyone Thought
        "TeamPCP, the threat actor behind an unrelenting flurry of attacks on open-source software this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop. The threat actor, which gained notoriety and has captivated threat hunters as it compromised and injected malicious code into more than 1,000 software packages in less than four months earlier this year, was also responsible for attacks dating back to 2020, Oligo Security found."
        https://cyberscoop.com/teampcp-long-active-history-2020-oligo-security/
      • From Stolen Credentials To Full Breach: The 72-Hour Timeline
        "A single compromised credential is often all it takes to turn an ordinary workday into a full-scale cybersecurity incident. Despite investments in firewalls, endpoint security, and identity controls, attackers continue to exploit one of the simplest yet most effective entry points—stolen usernames and passwords. Whether exposed through phishing campaigns, malware infections, credential-stealing infostealers, or data breaches, compromised credentials are readily traded across underground forums and dark web marketplaces. Once obtained, threat actors waste little time putting them to use. What begins as an unauthorized login can quickly escalate into privilege abuse, lateral movement, data exfiltration, and ransomware deployment—all within a matter of hours."
        https://cyble.com/blog/72-hour-timeline-credential-based-cyberattack/
      • One Adversary: The Moment Nobody Sees
        "Try a short exercise with your last serious fraud case. Draw the attack as the attacker ran it, stage by stage, and next to each stage write which of your teams could have seen it. Not which team caught it — which team’s telemetry contained it at all. For a typical phishing-to-fraud campaign, the answers come easily at first. The attacker registers a look-alike domain, sets up hosting and a certificate: your cyber team can see this — domain monitoring, certificate transparency, brand protection. Mass SMS and email lures go out to customers: cyber again, at least partially, through abuse reports and detection feeds. Skip ahead: the attacker logs in with stolen credentials and works around 2FA — your fraud team can see this, a new device, an unusual session. Funds move: fraud sees the damage."
        https://www.group-ib.com/blog/moment-nobody-sees/
      • Kali365 Exploits Microsoft Device Login To Access US Corporate Data
        "Kali365, a Phishing-as-a-Service (PaaS) platform, is targeting US companies with device code phishing that abuses Microsoft’s legitimate authentication process. The attack comes just a few months after the FBI warned that Kali365 was targeting Microsoft 365 accounts. By obtaining OAuth (Open Authorization) access and refresh tokens, attackers may gain continued access to corporate email, documents, and cloud services without directly stealing a password. For businesses, a single successful authorization can lead to data exposure, financial fraud, operational disruption, and higher incident response costs."
        https://hackread.com/kali365-exploit-microsoft-device-login-access-us-data/
        https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html
      • Fake Bank Of America "Action Needed" Phishing Email Deposits ScreenConnect Instead
        "We recently came across a fake Bank of America message that closely imitates the targeted bank's visual style, layout, and branding – from the initial phishing email, to the eventual webpage that victims are redirected to. The subsequent phishing page delivers an AccountGuard.zip with a .vbs file that contains a large chunk of base64-encoded data. The next phase of the attack then involves a complex chain of decoding scripts, and ends in the execution of arbitrary commands (with escalated privileges) in PowerShell."
        https://www.huntress.com/blog/bank-spam-rmm
        https://www.infosecurity-magazine.com/news/fake-bank-of-america-phishing-scam/
        https://www.helpnetsecurity.com/2026/08/05/fake-bank-of-america-email-account-guard/
      • From Open Lures To Cloaked Gates: How a MacOS ClickFix Campaign Learned To Hide
        "Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS), through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser. This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows. The blog details the domain pattern, fingerprinting checks, infection chain, detection coverage, and hunting pivots that defenders can use to identify related activity."
        https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/
        https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html
      • NullReceiver's Blank Crypto Transfers Solves The Challenges Of EtherHiding
        "We just identified a new blockchain-based command-and-control technique hiding inside two trojanized npm packages, bianira-ui and fluid-type-ui. Both are DPRK-linked clones of legitimate Tailwind CSS plugins, and both use the same trick to find their command server: they read it out of the destination address of a completely blank cryptocurrency transfer. We’re calling it NullReceiver, and we think it’s a deliberate improvement on EtherHiding."
        https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique
        https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html
      • COLDCARD Security Audit Phishing Attack Installs Remote Access Tool
        "A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. Proofpoint, which discovered the campaign, says it uses emails impersonating COLDCARD that claim a security audit is underway across its hardware cold storage wallet devices. The phishing campaign comes after attackers recently stole approximately 1,367 Bitcoin, worth an estimated $88.6 million, from 4,585 addresses using what is believed to be a random number generation flaw affecting multiple COLDCARD models and firmware versions."
        https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/
      • AI Has Enhanced Iran’s Asymmetric Playbook During The 2026 Conflict
        "Between January and June 2026, Tehran survived unprecedented military, economic, and political pressure by relying on its longstanding hybrid warfare model: blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control. Artificial intelligence (AI) enhanced these capabilities, acting as a force multiplier and almost certainly increasing the speed, scale, and effectiveness of Iranian operations. Ultimately, Iran demonstrated that its strategic resilience does not depend on possessing the most advanced AI capabilities; rather, the source of Iranian power remains the asymmetric playbook itself."
        https://www.recordedfuture.com/research/iran-ai-asymmetric-playbook
        https://assets.recordedfuture.com/insikt-report-pdfs/2026/ta-ir-2026-0716.pdf

      Breaches/Hacks/Leaks

      • Leaked n8n API Tokens Exposed Live Instances To Credential Theft
        "GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896 instances reachable at the time of testing, 321 accepted at least one leaked token. That means leaked credentials provided authenticated access to 36% of the reachable instances we tested, or roughly 26% of all hostnames identified in the commits."
        https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html
      • 311,000 Impacted By Brown Health Medical Group-MA Data Breach
        "Lifespan Physician Group of Massachusetts, doing business as Brown Health Medical Group-MA, is notifying over 311,000 individuals that their personal, medical, and financial information was stolen in a data breach. The incident occurred in December 2025 at its Hawthorn location. It involved a historic file server, the healthcare organization says in a sample notification letter filed with the Massachusetts Office of Consumer Affairs and Business Regulation."
        https://www.securityweek.com/311000-impacted-by-brown-health-medical-group-ma-data-breach/
        https://securityaffairs.com/196681/uncategorized/brown-health-medical-group-ma-data-breach-exposes-information-of-311000-individuals.html
      • Dutch Retailer De Bijenkorf Warns Customer Data May Be Exposed After Cyber Incident
        "A cyberattack on one of the logistics providers serving Dutch luxury department store chain De Bijenkorf has delayed customer orders, returns, and refunds while potentially exposing customer data. The incident is one of several in recent months that has disrupted retail and food companies through third-party contractors. The Amsterdam-based retailer said Wednesday that the incident affected only the systems of an external logistics partner and that there is currently no indication its own infrastructure was compromised."
        https://therecord.media/de-bijenkorf-luxury-retailer-third-party-cyber-incident
      • Brazilian Government Health Surveillance Platform Exposed 79GB Of Sensitive Data Online
        "Cybersecurity Researcher Jeremiah Fowler uncovered a data leak involving what appears to be a Brazilian government application and licensing portal containing personally identifiable information (PII) and shared his findings with ExpressVPN. We are publishing his report to help keep the public informed and protected as part of our ongoing effort to make the web a safer place."
        https://www.expressvpn.com/blog/brazil-sisvisa-data-exposed/
        https://hackread.com/brazil-health-surveillance-database-exposed-records/
      • Beacon CRM, Widely Used By Charities, Suffers Data Breach
        "Cloud-based customer relationship management software provider Beacon CRM said it's suffered a security breach that likely led to the theft of customer data. London-based Beacon said it first learned on July 29 that its systems may have been breached. Beacon says its CRM system is used by over 1,000 charities and non-profit organizations, ranging from Special Olympics Ireland and Great Lakes Outreach to Heart Research UK, to handle everything from collecting online donations, to managing memberships and selling tickets to events."
        https://www.bankinfosecurity.com/beacon-crm-widely-used-by-charities-suffers-data-breach-a-32420

      General News

      • Ransom Cartel Ransomware Creator Sentenced To 16 Years In Prison
        "Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. The U.S. Department of Justice announced today that the 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. The DOJ says Silnikau had been active on Russian-speaking cybercrime forums since at least 2005 and used the aliases "J.P. Morgan," "xxx," and "lansky.""
        https://www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/
      • Canadian Pleads Guilty To Snowflake Cloud Data-Theft Attacks
        "A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. ​26-year-old Connor Riley Moucka, also known as Alexander Moucka and Waifu, was arrested on October 30, 2024, for stealing data of hundreds of millions of individuals from companies using Snowflake’s storage service."
        https://www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/
        https://therecord.media/guilty-plea-snowflake-hack-connor-riley-moucka
        https://cyberscoop.com/connor-moucka-guilty-snowflake-attack-spree/
      • Google Blogger Locks Hundreds Of Blogs In Malware False Positive
        "Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites actually deleted from the platform. The issue began on August 4, and it appears to affect many legitimate blogs that do not host malware or have malicious scripts. As seen by BleepingComputer, hundreds of web admins have reached out to Google on the company's official forum for help in restoring access to their blogs."
        https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/
      • AI Sends Global Crime Syndicates Into Fraud Nirvana
        "In bad news for financial institutions, online retailers, cryptocurrency exchanges, and people in the dating pool who rely on identity verification to make sure they're not getting taken for a ride, global fraud gangs are aggressively industrializing their scam efforts. That's according to Eric Huber, senior manager for adversary intelligence and disruption at TD Bank, who said that major centers for organized crime specializing in financial fraud (notably in Southeast Asia and West Africa) are bypassing "know your customer (KYC)" rules and other identity-verification methods with an updated AI tool set that offers the ability to build completely believable synthetic identities capable of fooling even advanced AI-enabled behavioral defenses."
        https://www.darkreading.com/threat-intelligence/ai-global-crime-syndicates-fraud-nirvana
      • CSS: The Hidden Threat Lurking In Your Inbox
        "Using email platforms to target users is nothing new in the world of threat actors. Nor is it revolutionary for defenders who've shored up guardrails when it comes to suspicious attachments, malicious JavaScript, and more. But as these well-known threats take command of everyone's attention, another vector remains hidden in plain sight. While HTML is the structure that powers web pages, Cascading Style Sheets (CSS) address design and presentation of the page. From the text to colors and tags to images, CSS manages how a page is displayed. And according to Gareth Heyes, Web security researcher at PortSwigger, it can be weaponized because of its multiple capabilities."
        https://www.darkreading.com/cyberattacks-data-breaches/css-hidden-threat-lurking-inbox
      • Cybersecurity Skills Gap: More Than Just a Workforce Challenge
        "The cybersecurity skills gap is no longer just about filling open positions. Now, the challenge is how organizations can defend against an increasingly sophisticated, AI-powered threat landscape. The recently released Fortinet 2026 Cybersecurity Skills Gap Report reveals data that underscores how critical this challenge has become: 71% of organizations surveyed say the cybersecurity skills gap creates additional risk for their organization, and 86% experienced at least one breach in the past year. Regarding the breaches, more than half (56%) of the organizations attributed them in part to a lack of cybersecurity skills and trained IT security staff."
        https://www.fortinet.com/blog/industry-trends/cybersecurity-skills-gap-more-than-just-a-workforce-challenge
        https://www.fortinet.com/content/dam/fortinet/assets/reports/2026-cybersecurity-skills-gap-report.pdf
      • New Research: The Confidence Gap Between CISOs And Their Boards Is Real, And It’s Measurable
        "Boards of directors believe they understand their company’s security posture and what it means for the business. The security leaders presenting to them are far less sure. Only 12.5% of security leaders are very confident their board walks away understanding the true state of the program, and 55% of boards have never formally defined what cyber risk the company is willing to accept. Pulse Security AI unveiled these findings today in The CISO-Board Communication Gap, a research report drawing on more than 80 senior practitioners, examining how security leaders report to their boards and what gets lost between the two."
        https://hackread.com/new-research-the-confidence-gap-between-cisos-and-their-boards-is-real-and-its-measurable/
        https://pulsesecurity.ai/newsroom/ciso-board-communication-gap/
      • Your Enterprise AI Footprint Is About Three Times Bigger Than Your Model List
        "Organizations are building AI systems that combine models, agents and external tools instead of relying on standalone AI, according to Snyk’s latest State of Agentic AI Adoption report. The study analyzed 3,044 enterprise environments and 1.39 million code repositories to examine how enterprises are deploying AI. Of organizations using AI, 46.9% have adopted agentic architectures built on AI agents, model context protocol (MCP) servers, or both. More than half have deployed the full stack, combining AI agents with MCP infrastructure that enables access to enterprise data, applications, services and external tools."
        https://www.helpnetsecurity.com/2026/08/05/snyk-growing-agentic-ai-adoption-report/
      • Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
        "Prompt injection attacks continue to present the most dangerous threat from large language models (LLMs), despite the relatively low number of recorded incidents relating to this vector, according to an updated analysis from the Open Worldwide Application Security Project (OWASP). The non-profit foundation published the third version of its community-driven Top 10 for LLM Applications list, on August 4, 2026. For the third year in a row, practitioners listed prompt injection as the number one security challenge emanating from the use of GenAI tools."
        https://www.infosecurity-magazine.com/news/prompt-injection-llm-risk/
        https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
      • Cyberspace Is Now The Fourth Domain Of Military Conflict.
        "Geopolitics can be summarized as the behavior of a country or region influenced by its location in time (history and current events), and space (geographical proximity to other countries or regions). Those geopolitical actions are also influenced by the state of the economy and the psychology of its leaders. Geopolitical disagreements between countries are usually settled by diplomacy but sometimes by physical force of arms. The latter is usually a kinetic war involving, as necessary and available, land (an Army), air (an Air Force) and the sea (a Navy)."
        https://www.securityweek.com/the-fourth-battlefield-the-growing-role-of-cyber-operations-in-global-conflict/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c86b39c1-800b-43e5-9cf7-9e41d2c902f3-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ Langflow, N-central และ Apache Tomcat ที่ถูกใช้โจมตีจริงลงใน KEV

      CISA เพิ่มช่องโหว่ Langflow, N-central และ Apache Tomcat ที่ถูกใช้โ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ac1b7861-19ff-4319-885d-069961f6c5ae-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT