NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,610
    • กระทู้ 2,611
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • ช่องโหว่ Linux Kernel บน Ubuntu เสี่ยงหลุดจาก Container หลังมี Exploit เผยแพร่

      ช่องโหว่ Linux Kernel บน Ubuntu เสี่ยงหลุดจาก Container หลังม.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 182efd2c-d9f3-47a2-9c79-c72a07aeb67b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • นักวิจัยพบเทคนิค TrustSink ใช้ MFA Provider ปลอมขโมย Password ระหว่าง Login

      นักวิจัยพบเทคนิค TrustSink ใช้ MFA Provider ปลอมขโมย Password ร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 700cd314-449c-4686-a1d3-51a4a35b6f62-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • FBI เร่งตรวจสอบ เหตุกลุ่ม ShinyHunters อ้างการโจมตีเว็บไซต์สมัครงานและเข้าถึงข้อมูลเจ้าหน้าที่

      FBI เร่งตรวจสอบ เหตุกลุ่ม ShinyHunters อ้างการโจมตีเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6d94fb95-1241-42bb-a9be-d96d1de01b65-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 24 September 2026

      New Tooling

      • Prismor: Open-Source Runtime Control Plane For AI Agents
        "Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: allow, warn, or block. AI coding agents run shell commands, read and write files, handle credentials, and call outside APIs, often chaining many steps with little human review. Anyone running one is exposed to a poisoned file, issue, or web page that redirects the agent mid-task, to an agent that opens a .env file while debugging and sends its contents out, and to installs of compromised packages. Endpoint security tools watch the kernel and file system, so they only see what the agent does after the choice is made. PrismorSec built Prismor to step in before that point."
        https://www.helpnetsecurity.com/2026/09/23/prismor-open-source-ai-agent-security/
        https://github.com/PrismorSec/prismor

      Vulnerabilities

      • Check Point Warns Of Hackers Exploiting Security Gateway VPN RCE Flaw
        "Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. The same advisory also warns of threat actors exploiting a pre-authentication path traversal flaw tracked as CVE-2026-93616, which impacts the Management web service and can allow script execution and Java class loading. The company says that CVE-2026-93616 has been exploited as a zero-day since July 23."
        https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/
      • Critical Next.js ImageResponse Flaw Can Lead To Server Code Execution Via Crafted SVG Input
        "A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version 16.3.6. The flaw, tracked as CVE-2026-94545, affects Next.js 16.2.0 through 16.3.5 when ImageResponse runs on the Node.js runtime, which Next.js uses by default. Vercel's advisory rates it critical, with a CVSS score of 9.5. The Edge version of ImageResponse is not affected, and neither is Next.js 15."
        https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html
      • CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After The Patch
        "Yesterday we wrote up CVE-2026-87902, the unauthenticated local file inclusion in WordPress page template resolution fixed in 7.1.2. That post covered the sink, the preconditions and the fix. This is the follow-up on what we are seeing hit our firewall. Update, 23 September 2026: when this post first went up, every request we had seen was reconnaissance against harmless core files. That is no longer true. Attackers are now including pearcmd.php and using it to write PHP files to disk, and public scanning tooling for this CVE is in circulation. The Update section below covers what changed. The original first day analysis is kept underneath it as a record."
        https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/
        https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/
        https://securityaffairs.com/199564/hacking/cve-2026-87902-how-close-is-your-wordpress-to-remote-code-execution.html
        https://www.helpnetsecurity.com/2026/09/23/cve-2026-87902-wordpress-7-1-2-security-release/
      • F5 Patches BIG-IP APM Zero-Day Flaw Exploited In RCE Attacks
        "F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. BIG-IP APM (short for Access Policy Manager) is the company's centralized access management proxy solution that helps admins secure access to their organizations' networks, applications, cloud, and application programming interfaces (APIs). Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server."
        https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/
        https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html
        https://www.theregister.com/security/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm/5298659
        https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/
        https://securityaffairs.com/199619/security/f5-big-ip-apm-zero-day-exploited-in-zero-day-rce-attacks.html
      • New cPanel Flaw Lets a Hosting Account Run Code As Root, Take Full Server Control
        "A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both, along with a fix for a third flaw in the same service, which stores each account's calendars and contacts. That third flaw lets a local user on the server read other accounts' calendar events and contacts, but not change them or gain root access."
        https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html
      • Adobe Patches Critical Flaws In Connect, AEM Forms
        "Adobe on Tuesday rolled out patches for 36 vulnerabilities across its products, including critical-severity flaws in Connect and Experience Manager (AEM) Forms. The Adobe Connect update resolves nine security defects, including six critical issues that could be exploited for arbitrary code execution and privilege escalation. Tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, they are described as SQL injection, cross-site scripting (XSS), and improper input validation flaws."
        https://www.securityweek.com/adobe-patches-critical-flaws-in-connect-aem-forms/
      • Chrome 154 Patches 108 Vulnerabilities
        "Google on Tuesday announced the release of Chrome 154 to the stable channel with patches for 108 vulnerabilities, including 11 critical-severity bugs. The critical security defects include buffer overflows (three in ANGLE and one in WebGL), out-of-bounds writes (two in GPU and one in WebGL), and use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter. Nine of the critical issues were reported by external researchers. In total, 32 of the newly patched flaws were reported externally, while the rest were discovered by Google."
        https://www.securityweek.com/chrome-154-patches-108-vulnerabilities/
      • Send GitLab An Email, Push To Main
        "GitLab projects have a button labeled "Email work item to this project". If you click it, GitLab shows you a private email address. Email anything to that address and a new issue appears in that project, authored by you. incoming+project-id-glimt-XXXXXXXXXXXXXX-issue@incoming.gitlab.com. The glimt- string in the middle of that address is a credential. It's a long-lived token tied to your account, and it never expires."
        https://www.aikido.dev/blog/gitlab-email-push-to-main
        https://www.darkreading.com/application-security/gitlab-email-addresses-supply-chain-attacks
        https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html
      • MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password Or SSH Key
        "Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. As previously reported, CERT Polska warned on September 5 that attackers were using RouterOS flaws to take control of devices whose SSH service was reachable from public networks."
        https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html
      • Containers Are No Longer a Security Boundary
        "Containers are generally considered as a robust security isolation boundary and are widely used to isolate workloads across enterprise and cloud environments. As AI accelerates kernel vulnerability discovery and exploitation, the barrier to escaping containers by attacking kernel has fallen so significantly that we must assume attackers can do so at will. There are nearly 6000 kernel CVEs published as of September 2026. In this post, we demonstrate such a case using CVE-2026-80521, a Linux kernel use-after-free vulnerability in the AF_UNIX subsystem discovered with dfs-large1. The exploit code is available on GitHub. Organizations should move sensitive and untrusted workloads to stronger isolation technologies such as Firecracker or Kata Containers."
        https://depthfirst.com/research/containers-are-no-longer-safe
        https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html
      • Stealing OAuth Tokens Through Microsoft's Front Door
        "I was hunting for the next regsvr32. Not that binary specifically, but its category: a Microsoft-signed binary already on every Windows box that will fetch remote code and run it, so an attacker never has to drop anything unsigned. I pulled a catalog of signed binaries that don't appear in LOLBAS and filtered for anything that could reach the network and execute what it got back. The AppX web-host family came up in that filter, and one binary stood out. WWAHost.exe, the Windows Web App Host, will render whatever web content an AppX package points it at. That alone makes it interesting. However, what made me stop was the manifest flag: declare WindowsRuntimeAccess="all" and the remote JavaScript it renders doesn't just run, it inherits the full Windows Runtime API surface, including the API that drives OAuth sign-in. That was the moment it clicked as an attack. If a page I controlled could reach that sign-in API, it could stand up a real Microsoft login and pocket the tokens it handed back. I wanted to know if it actually worked."
        https://www.huntress.com/blog/stealing-oauth-tokens-through-microsofts-front-door

      Malware

      • Placeholder Domain Used In Dev Docs Now Serves ClickFix Attacks
        "The "third-party[.]com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. The domain third-party[.]com has long been used in documentation to represent an arbitrary external website, API, or service, similar to how developers use domains such as example[.]com. However, unlike example[.]com, example[.]net, and example[.]org, which IANA reserves specifically for documentation, third-party[.]com is a normally registered domain whose content its owner can control."
        <https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-* serves-clickfix-attacks/>
      • RemControl: AI Built The Overlays. Victims Lose Their PINs
        "Group-IB researchers have discovered a previously undocumented Android banking trojan, internally named RemControl by its operator, targeting retail banking customers across Western Europe, the Middle East, and Canada. The malware abuses Android’s Accessibility Service to inject phishing overlays over legitimate banking applications, stream the device screen in real time, log keystrokes, and provide the operator with full remote control over infected devices. It is distributed through fake Google Play Store pages impersonating the TVTap IPTV application, with malvertising campaigns confirmed as one of the delivery channels."
        https://www.group-ib.com/blog/remcontrol-android-banking-trojan/
        https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/
      • Autonomous AI Agents Are Breaking Into Hundreds Of Online Retailers For $25 a Target In An Ongoing Campaign
        "A financially motivated threat actor is using open source AI harnesses to attack hundreds of online retailers, at a marginal cost of tens of dollars per company. Gambit Security's Threat Intelligence team recovered the operator's staging server and reconstructed the campaign from it. Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees. The activity goes back to July 2026 and is still running."
        https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company
        https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/
      • Dark Sourcery: How Hackers Manipulate AI To Scam You
        "ChatGPT, Gemini, and Google AI Overview are being poisoned by a massive AI disinformation attack. When users look up everyday info of hundreds of major companies, AI is delivering phishing traps disguised as trusted answers. Attackers are flooding the web with carefully optimized posts, PDFs, reviews, and fake support pages, to trick AI into presenting fraudulent phone numbers, email addresses, and login pages. The targets included Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb, TripAdvisor, and hundreds more."
        https://medium.com/@arielsimon/dark-sourcery-how-hackers-manipulate-ai-to-scam-you-88df434d2073
        https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign
      • DarkMe Email Campaign Broadens Targeting For APT RAT
        "DarkMe, a Visual Basic 6 (VB6) spy trojan and remote access tool became well known in February 2024 for its use of zero days to deliver malware. But this malware family was first observed in September 2021 and publicly documented a year later by NSFOCUS under "Operation DarkCasino" attributed to a group called EvilNum. Researchers at Trend Micro and SonicWall have also tied this malware, with the usual attribution caveats, to Water Hydra, an APT group with the unusual profile of chasing money rather than espionage. Its campaigns are typically financially motivated, targeting forex traders, stock-trading forums, online gambling platforms, and cryptocurrency users."
        https://www.huntress.com/blog/darkme-rat-abandons-exploits
        https://www.helpnetsecurity.com/2026/09/23/darkme-rat-phishing-email-hits-corporate-targets/
      • Fake Claude Max Giveaway Hides a Google Account Phishing Trap
        "Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap
        https://www.helpnetsecurity.com/2026/09/23/fake-claude-max-giveaway-phishing/
      • x47.c Botnet Comes With 18 Attack Methods, Including AI API Draining
        "x47.c is a previously undocumented Windows botnet advertised with 18 attack methods, credential theft, SOCKS5 proxies, and an AI module designed to help it remain on infected machines. Qrator Research Labs identified the offering, sold by WraithTools, during routine threat hunting. One of the advertised methods, “AI API drain,” is designed to exhaust a victim’s paid AI credits. Using a valid API key, an operator can send repeated requests that consume the account’s balance or increase its bill. OWASP describes this type of attack as Denial of Wallet (DoW)."
        https://qrator.net/blog/details/x47.c-botnet
        https://www.infosecurity-magazine.com/news/x47c-botnet-ai-api-draining-18/
      • MemTensor Npm And PyPI Packages Hit By a Go Worm
        "On September 23, 2026, an attacker published malicious versions of two MemTensor packages. The affected packages are the OpenClaw plugin @memtensor/memos-cloud-openclaw-plugin on npm and the MemOS Python library MemoryOS on PyPI. Both versions contain the same Go implant, sckit. The binary runs in the background each time the package loads. It collects credentials from the home directory and sends them to servers under skyleen[.]fr. It also includes the code it needs to copy itself into other repositories and packages that the stolen credentials can reach. The attacker got the publish tokens from MemTensor’s own GitHub Actions release pipelines. To do this, they pushed commits that made the release job hand its npm or PyPI token to the attacker before the job published anything."
        https://safedep.io/memtensor-sckit-worm-npm-pypi/
        https://www.aikido.dev/blog/supplychain-local-memtensor-npm-pypi
        https://socket.dev/blog/memtensor-compromise
        https://www.stepsecurity.io/blog/sckit-supply-chain-worm-hits-memtensor-npm-pypi-scopes
        https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html
      • Meet AvisLoader: A Windows Loader Built To Outlast a Takedown
        "Varonis Threat Labs recently discovered AvisLoader, a new Windows loader named after the Latin word for bird. We found it on an exposed staging server alongside a ClickFix lure, supporting tools, and its Command Center. The attack starts with a familiar ClickFix lure. A page posing as a document-signing request asks visitors to copy and run an attacker-supplied command on their machine. The more interesting part is how AvisLoader stays connected. It communicates via Tox, an encrypted peer-to-peer (P2P) messaging network that carries commands and additional payloads from the operator."
        https://www.varonis.com/blog/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown
      • Operation Conflict Compass: Konni Targets Ukraine Via Malicious LNK Lures
        "Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs. Recently, the SOCRadar Threat Research Unit (STRU) uncovered Operation Conflict Compass, a targeted campaign by the DPRK-aligned actor Konni, aimed at gathering intelligence on the ongoing trajectory of the Russian invasion of Ukraine."
        https://socradar.io/blog/operation-conflict-compass-konni-ukraine-lnk-lure/

      Breaches/Hacks/Leaks

      • GitHub App Private Keys: 474 Leaked Keys Exposed
        "Supply-chain security has been a hot topic in recent years. Threat actors have exploited the npm, PyPI, and Rust ecosystems to compromise developer machines at scale, and GitHub has played a central role as an entry point through badly configured Action workflows. GitHub Apps are a lesser-explored vector in that same landscape. Because of the privileges they hold, they are one of the most sensitive components in the GitHub ecosystem, capable of reaching into every repository an installation covers and, in the worst cases, taking over the organizations that installed them. The recent CISA leak showed exactly how far that reach can go: a single compromised App became an open door into the organization's information system."
        https://blog.gitguardian.com/github-app-private-keys-leaked/
        https://www.infosecurity-magazine.com/news/hundreds-leaked-github-app-keys/

      General News

      • InfraTrust Report Warns Network Management Systems Under Attack
        "Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. This was reported in the September edition of Eclypsium's InfraTrust Pulse, a monthly report tracking security advisories affecting network devices, servers, firmware, chips, and other infrastructure. Between August 25 and September 17, InfraTrust tracked 158 new security advisories across 17 vendors, covering 1,699 vulnerabilities."
        https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/
        https://pulse.infra-trust.org/september-2026/
      • Ryuk Ransomware Member Sentenced To 24 Months In Prison
        "An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. 35-year-old Karen Serobovich Vardanyan (also known online as "Maneeken" or "Karl Lagerfeld"), who specialized in gaining initial access to corporate networks, pleaded guilty in July after being extradited from Kyiv, Ukraine, following his April 2025 arrest. According to court documents, Vardanyan hacked into the networks of multiple U.S. organizations in Ryuk ransomware attacks between March 2019 and approximately June 2020."
        https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/
        https://therecord.media/ransomware-ryuk-sentenced-doj
        https://cyberscoop.com/ryuk-ransomware-operator-karen-vardanyan-sentenced/
      • CISA Lays Out Future Of CVE Vulnerability Program
        "The U.S. Cybersecurity and Infrastructure Security Agency published a short whitepaper Wednesday, laying out four "dimensions of quality" it will pursue to improve the Common Vulnerabilities and Exposures program it oversees, which catalogs and characterizes newly discovered software vulnerabilities. The CVE program is widely regarded as one of the world's most trusted and widely used cybersecurity public goods. It's employed by cyber defenders all over the world. Its future is a matter of enormous importance to the large cybersecurity vendor ecosystem that has grown up around vulnerability prioritization and management."
        https://www.bankinfosecurity.com/cisa-lays-out-future-cve-vulnerability-program-a-32912
        https://cyberscoop.com/cisa-cve-data-quality-white-paper-expert-reaction/
      • How The CISO-CMO Alliance Builds Trust Before Crisis Strikes
        "Chief information security officers (CISOs) and chief marketing officers (CMOs) sit at the intersection of a critical tension: CMOs seek to leverage vast pools of customer data to drive growth, brand loyalty, and market share. CISOs work to minimize risk exposure and protect that same data. But rather than viewing these objectives as opposing forces, forward-thinking organizations recognize that CISO-CMO alignment is foundational to a competitive advantage. Unfortunately, as is often the case, if this relationship isn't already established, miscommunication and misalignment can turn a security incident into a brand disaster."
        https://www.darkreading.com/cybersecurity-operations/how-ciso-cmo-alliance-builds-trust-before-crisis
      • Cyberthreats To The Gulf States In H1 2026
        "A high level of economic development, a key role in the global energy sector driven by oil and gas exports, and heavy investments in digital technologies make the Gulf states an attractive target for financially motivated cybercriminals. Additionally, the tense geopolitical climate in the region has led to increased activity from hacktivists and advanced persistent threat (APT) groups. This report analyzes the cyberthreat landscape in the Gulf states during the first half of 2026. The countries covered include Bahrain, Iraq, Iran, Kuwait, Oman, Qatar, Saudi Arabia, and the United Arab Emirates (UAE)."
        https://positechglobal.com/en/research/analytics/cyberthreats-to-the-gulf-states-in-h1-2026/
        https://www.darkreading.com/threat-intelligence/uae-saudi-arabia-face-onslaught-of-increasingly-sophisticated-automated-cyberattacks
      • Cloud Intrusions Now Move At Machine Speed
        "Cloud-native environments are vital to AI initiatives and business transformation. That also makes them high-value targets. Fortinet FortiCNAPP intelligence shows that threat actors are now using automated attack workflows to identify vulnerable deployments, breach them, and quickly turn access into profit. The 2026 Cloud-Native Threat Landscape Report draws exclusively on FortiCNAPP intelligence to examine the scale of adversary activity, the paths attackers use, the gaps they exploit, and the actions security leaders must now take to strengthen cloud resilience and accelerate defender velocity."
        https://www.fortinet.com/blog/industry-trends/cloud-intrusions-now-move-at-machine-speed
      • Nearly Two-Thirds Of Tested Websites Fail Every Bot Test
        "Malicious bot activity increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Traffic from AI agents and large language model crawlers rose 82.3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026. The company analyzed trillions of requests across more than 75,000 customer sites during the 12-month period. Bots and AI agents generated approximately 26.5% of all traffic in the dataset."
        https://www.helpnetsecurity.com/2026/09/23/datadome-growing-bad-bot-traffic-report/
      • Ransomware Attacks Reach Record High For 2026
        "Over 1000 organizations globally were hit with ransomware attacks during August, as the number of cyber extortion campaigns reached a new high for 2026, analysis of incidents has warned. According to NCC Group’s Cyber Threat Intelligence Report for August 2026, published on September 23, 1073 companies fell victim to ransomware attacks during the month. The report stated the figure represented a record high for 2026 and a 12% increase on the 973 organizations hit by ransomware attacks during July. During August, North America was the most common target for ransomware attacks, accounting for 44% of incidents, organizations in Europe accounted for 26% of known incidents, while 13% of ransomware attacks targeted victims in Asia."
        https://www.infosecurity-magazine.com/news/ransomware-attacks-reach-record/
      • EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
        "The EU’s top audit institution has criticized the union for various “shortcomings” that are hindering its detection and response to large-scale cyber incidents. The EU Court of Auditors said in a new report that the bloc’s €1.4bn ($1.6bn) budget for cybersecurity is doing some good, but that it suffers from an Achilles heel, “The insufficient exchange of information.” A lack of formally defined roles is hampering cooperation between country-level CSIRTs and European Cyber Crisis Liaison Organisation Network (EU-CyCLONe), it warned."
        https://www.infosecurity-magazine.com/news/eu-auditors-slam-blocs-cyberinfo/
      • Anthropic And OpenAI Models Still Attempt Restricted Actions In Safety Tests
        "Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands of simulated scenarios." The AI company said the model is less likely than its other recent models to carry out hard-to-reverse actions or act outside the boundaries it's been given, adding it's more resistant than Opus 5 to prompt injection."
        https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html
      • Latvia Arrests Suspected Hacker For Electronics Repair Company Breach
        "Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — using similar methods — was discovered in early September at TSC, an electronics repair company belonging to Latvian telecommunications group LMT."
        https://therecord.media/latvia-hacker-arrest-cyberattack
      • A Look At AI Doomsday Scenarios That Researchers Say Could Put Humanity At Risk
        "For years, artificial intelligence researchers have warned of ways the technology could wipe out humanity: AI bots could design an unstoppable disease, unleash a nuclear war, or transform all of Earth into paper clip factories, as one thought experiment goes. Debates inside the AI industry and beyond over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons. Despite warnings of the potential for humans to lose their grip on the technology, some suspect the worst-case scenarios described by the AI companies themselves have more to do with validating the importance of their work than reality."
        https://www.securityweek.com/a-look-at-ai-doomsday-scenarios-that-researchers-say-could-put-humanity-at-risk/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 35ca38ff-ea20-42c8-a6e0-def15a987a6b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Microsoft เตือนช่องโหว่ CVE-2026-65660 ใน SharePoint อาจนำไปสู่การรันคำสั่งบนเซิร์ฟเวอร์

      Microsoft เตือนช่องโหว่ CVE-2026-65660 ใน SharePoint อาจนำไปสู่กา.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e5a469f3-c2bc-4972-930a-a8efc5f74e4f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • BigCommerce แจ้งเหตุข้อมูลรั่วไหล หลัง Credential ของแอป Ribon ถูกใช้ฝังสคริปต์อันตรายบนร้านค้าออนไลน์

      BigCommerce แจ้งเหตุข้อมูลรั่วไหล หลัง Credential ของแอป .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5fe31742-90a5-446e-bb24-84c2ed859d04-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้ไม่หวังดีเจาะระบบควบคุมการผลิตน้ำประปาในรัฐโคโลราโด สหรัฐอเมริกา

      ผู้ไม่หวังดีเจาะระบบควบคุมการผลิตน้ำประ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9ca85fac-7789-4c7f-a529-f33ddff3558d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 23 September 2026

      Industrial Sector

      • LwIP TCP/IP Stack MQTT Client Application
        "Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01
      • LwIP (Lightweight IP)
        "Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02
      • Siemens Siveillance Control
        "A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-03
      • Siemens Industrial Edge Management
        "Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-06
      • Siemens SIMOVE Fleetmanager And SIPLANT
        "SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-07
      • Siemens SIPLUS And SIMATIC Products
        "Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-04
      • Siemens Desigo CC Family
        "A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-05
      • Siemens WTV676 And WTV776
        "The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-08
      • OpenPLC Runtime v3
        "Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-09
      • Operational Technology Scope Expands As Security Matures
        "Serious cybersecurity incidents involving operational technology systems carry a cost, averaging over 16 hours of downtime and losses of up to $500,000 per hour. As a result, more industrial organizations report putting plans and capabilities in place designed specifically to prevent such downtime, or to minimize operational disruption when it does occur. Those findings come from Honeywell Technologies' inaugural 2026 Operational Technology Cybersecurity Benchmark Report, based on studies conducted by ISMG advisory firm CyberTheory."
        https://www.bankinfosecurity.com/operational-technology-scope-expands-as-security-matures-a-32890
        https://www.honeywell.com/us/en/insights/research/2026-ot-security-benchmark
      • Beyond The Pipes: The Identity Exposure Hiding In U.S. Water Utility Vendors
        "Recent attacks against U.S. water and wastewater systems have put a spotlight on exposed operational technology – PLCs (programmable logic controllers) and HMIs (human-machine interfaces) reachable from the public internet, still running default passwords. That’s a real problem, and CISA has said so directly. But it’s not the only one. SpyCloud researchers collated a target database of 66,845 EPA-registered drinking-water and wastewater systems and completed a record-level identity analysis on 10,000 of those organizations, spanning utilities, and the ICS/OT and water-technology vendors that supply them. What we found: identity exposure runs through this sector on its own track – separate from, but just as urgent as, the OT risk making headlines."
        https://spycloud.com/blog/water-utility-identity-exposure/
        https://cyberscoop.com/spycloud-study-water-utilities-infostealer-exposure/
      • More Than a Third Of Industrial Orgs See Cybersecurity Risk As a Top Obstacle To Growth, Study Finds
        "Rockwell Automation, Inc. (NYSE: ROK), the world’s largest company dedicated to industrial automation and digital transformation, today released “Operational Resilience in the Age of Connectivity,” an industry insights report based on input from 1,500 manufacturing and industrial operations decision makers across 17 countries. The research reveals a disconnect between confidence in comprehensive cybersecurity protection and operational risk. Although industrial organizations are investing in cybersecurity, those investments do not automatically translate into operational resilience."
        https://www.darkreading.com/cyber-risk/third-industrial-orgs-see-cybersecurity-risk-top-obstacle
        https://www.rockwellautomation.com/en-us/capabilities/industrial-cybersecurity/operational-resilience-in-the-age-of-connectivity2.html

      New Tooling

      • Introducing CAIRN: Frontier Tracking For AI-Integrated Malware
        "A cairn is a marker left behind on a trail, a deliberately placed stack of stones that helps hikers find their way when the path is unclear. Attackers building AI-integrated malware unintentionally (and inevitably) leave behind markers of their own: prompt templates, provider endpoints, API keys, jailbreak terms, and other artifacts embedded throughout their tooling. When we consider these strings as cognitive artifacts, or vestiges left behind from AI integration, we can enable a new, metadata-first hunting methodology for AI-integrated malware that is fast and scalable. These artifacts can be extracted, related, and classified without ever touching the underlying binary."
        https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/
        https://www.helpnetsecurity.com/2026/09/22/cairn-open-source-framework-ai-malware-closedquorum/

      Vulnerabilities

      • Security Advisory – Action Required – Active Exploitation Of CVE-2026-85102 And a Management Pre-Authentication Vulnerability CVE-2026-93616
        "As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two vulnerabilities affecting Security Gateway and Security Management: A fix for CVE-2026-85102 has been available since September 9, and customers who have applied it are already protected. CVE-2026-93616 is a newly discovered zero-day vulnerability in Security Management, and a fix is available now as part of this advisory."
        https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
        https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/
        https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
        https://securityaffairs.com/199549/security/check-point-fixes-a-new-actively-exploited-critical-security-flaw.html
      • D-Link Warns Of Max Severity Zero-Day Bug In DIR-822A Routers
        "D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. This security flaw stems from a stack-based buffer overflow and improper data handling in the DHCP server component and can be exploited without authentication or user interaction. Attackers without valid credentials on the same local network can send crafted DHCP packets to the device, trigger the overflow, and potentially crash the DHCP daemon or achieve remote code execution on targeted devices."
        https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/
        https://www.bankinfosecurity.com/d-link-flags-max-severity-zero-day-in-legacy-router-a-32896
      • JFSA-2026-001686326 - Bifrost Is Vulnerable To Unauthenticated Remote Code Execution Via MCP Stdio Client Registration
        "Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image). The HTTP request may time out. The process is already running. transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it. The 1.6.x line through 1.6.11 does not contain the fix."
        https://research.jfrog.com/vulnerabilities/bifrost-is-vulnerable-to-unauthenticated-remote-code-execution-via-mcp-stdio-client-registration-cve-2026-90898/
        https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html
      • New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited In Certificate-Based Setups
        "Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are exposed. As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista has already patched the Hosted and Dedicated versions of VCO. The affected releases include those that fixed a different VCO flaw, which Arista reported as exploited in July."
        https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
      • WordPress 7.1.2 Security Release: Unauthenticated LFI To RCE
        "WordPress 7.1.2 landed on 22 September 2026. It’s a security-only release with a single fix, and that fix is the most serious thing WordPress has patched in a while: an unauthenticated local file inclusion in page template resolution that can reach remote code execution. Patchstack customers are protected by a RapidMitigate rule. We still recommend updating to the most recent version of WordPress available."
        https://patchstack.com/articles/wordpress-7-1-2-security-release-unauthenticated-lfi-to-rce/
        https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html
      • SharePoint Flaw Initially Listed As Spoofing By Microsoft Enables Authenticated RCE
        "A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been available since the August 11 security updates, and the National Vulnerability Database scores it 8.8."
        https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
      • Comment2Shell: Zero-Click Pre-Auth XSS To RCE In WordPress Core
        "This blog post is about an unauthenticated stored XSS vulnerability in WordPress core, tracked as CVE-2026-93485. If you use WordPress, please update to at least version 7.1.1, or to the latest release in your branch. The fix was backported to every supported branch down to 4.7.36."
        https://idnsec.com/research/comment2shell-zero-click-pre-auth-xss-to-rce-in-wordpress-core/
        https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
        CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
        CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
        CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog
      • New Windows Defender Zero-Day Blocks Microsoft Antivirus Updates
        "Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. Naceri named it BigDiskBuster and said it is similar to another Defender zero-day known as UnDefend, which he released in April and that allowed standard users to block definition updates. The security researcher added that BigDiskBuster works on all supported Windows versions and that it needs to run in the background to block Defender updates."
        https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
        https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html
        https://www.theregister.com/security/2026/09/22/nightmareeclipses-latest-zero-day-leaves-microsoft-defender-stuck-in-the-past/5298320
        https://www.securityweek.com/nightmare-eclipse-drops-new-microsoft-defender-exploit-after-revealing-identity/
        https://securityaffairs.com/199538/hacking/chaotic-eclipse-released-bigdiskbuster-a-poc-for-windows-defender-update-dos-zero-day.html
      • Meta’s Muse AI Assistant Has a Zero-Day That Can Turn It Into a Mac Backdoor
        "Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.” Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting with email and calendars."
        https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor
        https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html
      • New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access To Host Memory
        "A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine. The affected code is part of the mainline Linux kernel for ARM64, and it is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1."
        https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html

      Malware

      • Larva-25012: A 2026 Proxyware Distribution Campaign By The Threat Actor (DigitalPulse, SOAX, Appsalt, IPRoyal)
        "The AhnLab SEcurity intelligence Center (ASEC) has been monitoring proxyjacking attacks and confirmed that, in the second half of 2026, the Larva-25012 threat actor has resumed actively distributing Proxyware. Rather than conducting malware distribution through new methods, the threat actor appears to have targeted already infected systems to distribute Proxyware."
        https://asec.ahnlab.com/en/95516/
      • Open Season On Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
        "GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We are withholding the exact IP address due to victim sensitivities and operational risk. Once these factors have been mitigated, GreyNoise will publish an update."
        https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation
        https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/
      • The Closed Quorum: Inside The First Reported Autonomous AI C2 Implant
        "AI’s impact on offensive cyber operations has thus far mainly focused on two dimensions: speed and scale. Attackers can generate phishing lures faster and produce more malicious code variants with less effort. These are real effects, visible in the proliferation of AI-generated coding samples and agent-assisted intrusions that have become common in the past few years. But in each case, the human operator remains present: directing the tooling, selecting targets, and guiding the execution. AI makes the operator faster and more productive but does not remove them from the operation."
        https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/
        https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/
        https://www.theregister.com/security/2026/09/22/windows-closedquorum-malware-uses-ai-models-to-autonomously-select-post-compromise-actions/5298435
      • From Payment Plan To Ransomware - Inside a Global Group Attack
        "Highly sophisticated ransomware now targets industries worldwide. Today’s ransomware allows threat actors to infiltrate networks, encrypt confidential data, and hold critical systems hostage until a cryptocurrency ransom is paid. Worse, threat actors often employ “double extortion” techniques by stealing sensitive company data and threatening to publish data publicly if the ransom is not paid. By weaponizing a company’s digital assets against itself, ransomware stands as the most severe cybersecurity threat to modern business operations."
        https://cofense.com/blog/from-payment-plan-to-ransomware-inside-a-global-group-attack
      • Mind The (Patch) Gap, Part 2: Fake Websites Used To Deploy Chrome & Windows 0-Day Exploits
        "On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) actors. Shortly after that blog post was published, Volexity discovered additional campaigns—this time from a third Chinese threat actor, tracked by Volexity under the alias UTA0565—that used the same chained exploits on September 3-4, 2026, while the vulnerabilities were still unpatched. Notably, this threat actor’s campaigns differed from previously documented attacks by using multiple fake websites to deceive victims."
        https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/
        https://cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/
      • Relaying To The Frontier
        "Team Cymru has uncovered 10,000+ hidden gateway servers masking malicious activity originating in China that bypassed AI providers' region bans and potentially siphoned proprietary model outputs. This discovery now equips our customers and partners to detect and stop the abuse of frontier AI models, preventing exorbitant recovery costs, and compliance and IP exposure."
        https://www.team-cymru.com/post/llm-gateway-frontier-model-abuse
        https://www.darkreading.com/cyber-risk/relays-masking-chinese-access-frontier-ai-models
      • Spraying In The Andes: TeamFiltration Returns To Exploit Forgotten Service Accounts
        "Proofpoint researchers identified an active TeamFiltration campaign - tracked as UNK_CondorFiltration, that targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America, focusing intensively on Chilean organizations. All 7 successfully compromised accounts were unmanaged functional/service accounts with no prior legitimate login baseline, strongly indicating default or predictable passwords that had never been rotated, with no MFA enforcement. Several compromised accounts showed post-access activity beyond the initial credential validation: the attacker signed in from a German VPN node, attempted to authenticate to the corporate VPN, and accessed several Azure apps, including OfficeHome, Azure Portal, and SharePoint Online."
        https://www.proofpoint.com/us/blog/threat-insight/Spraying-in-the-Andes-TeamFiltration-Returns
      • Malicious Npm Campaign Targets Developers Integrating Twilio
        "The volume of malware on public repositories hasn’t decreased. ReversingLabs (RL) has never seen more malicious packages published on public repositories, and the overall count of malicious software is steadily rising. Looking at the metrics, npm saw around 5308 unique malicious packages published in 2024 (excluding spam). By August of this year, the number of malicious npm packages reached 5723, exceeding the total for all of 2024 in just eight months. And the number of malicious packages continues to grow."
        https://www.reversinglabs.com/blog/malicious-npm-campaign-twilio
        https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html
      • SideCopy Threat Intel: MSHTA-Driven Execution And RAT Deployment
        "The modern cyber warfare landscape has evolved significantly as threat actors pivot toward simple yet highly effective and evasive malware. While the primary objective of advanced persistent threat (APT) groups like SideCopy has historically been the surveillance and exfiltration of sensitive data from government officials and high-ranking personnel, their strategic scope has recently broadened to include academic institutions. SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols. This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure."
        https://www.trellix.com/blogs/research/sidecopy-threat-intel-mshta-execution-rat-deployment/
        https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html
      • Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
        "Modern Endpoint Detection and Response (EDR) platforms have made traditional malware injection techniques significantly harder to execute. In most cases, if a threat actor attempts to write malicious code into a process, an alert will fire. However, that sense of security is being actively challenged as cybercriminals and red teams find new ways to blend malicious payloads into standard operating system routines. Flashpoint’s Intelligence team built and tested a proof-of-concept for a newly disclosed technique known as Process Parameter Poisoning. By compiling a custom payload and layering evasion mechanics, our analysts demonstrated how easily traditional API hooks can be rendered blind in a laboratory environment—achieving zero alerts across tested EDR/XDR controls."
        https://flashpoint.io/blog/process-parameter-poisoning-edr-evasion-technique/
      • Npm Supply-Chain Attack Abuses Trusted Publishing To Ship GHAPPIER Loader
        "A high-severity supply-chain attack was disclosed affecting the npm package @dforge-core/dforge-mcp, allowing attackers to distribute a remote-shell implant via a legitimate-looking update carrying valid npm provenance signatures. Due to the potential for full system compromise and the difficulty of forensic detection, immediate action is recommended for any organization that consumed version 0.2.21."
        https://orca.security/resources/research/ghappier-loader-npm-supply-chain-attack/
      • Graphalgo Campaign Spreads To Terraform Providers And Go Modules
        "We’ve identified Go malware distributed via at least two Terraform providers and at least two Go Modules. This is the first time we’ve observed malware distributed via Terraform providers. The malware overlaps with the Graphalgo NPM malware campaign, first reported by ReversingLabs in February 2026, and also reported on in the last week by Safedep, CheckMarx, and JFrog. The malware is a Go port of the Graphalgo malware that shares blockchain and Slack infrastructure and a public key with recent JavaScript samples distributed via NPM. The threat actor has also created at least two fake Go ecosystems to help promote its packages, suggesting an ongoing interest in the Go ecosystem."
        https://www.aikido.dev/blog/graphalgo-terraform-go-modules

      Breaches/Hacks/Leaks

      • ShinyHunters Claims FBI Hack, Data Theft In PeopleSoft Zero-Day Breach
        "The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure. ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records."
        https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
        https://cyberscoop.com/shinyhunters-claims-fbi-attack/
        https://www.theregister.com/security/2026/09/22/shinyhunters-claims-fbi-hack-this-is-not-financially-motivated/5298385
      • Elsevier.com, Evolve And Manuscript Submission Redirected To LAPSUS$ For At Least 78 Minutes
        "For at least 78 minutes on the evening of September 21, Elsevier's own homepage served an extortion page. Typing www.elsevier.com landed visitors on a site branded LAPSUS$ GROUP, Chapter II, carrying a signed statement that taunted the FBI and counted down to a future victim. It was not a lookalike domain and not a phishing email. The real address went to the attacker's page. Two other Elsevier properties did the same: submit.elsevier.com, where researchers upload manuscripts for peer review, and evolve.elsevier.com, the platform American nursing programs use for HESI exams and coursework. ScienceDirect was unaffected throughout. This was not ransomware. Nothing was encrypted and no Elsevier data has been claimed by anyone. What is confirmed is narrower and, in one specific way, worse: for the length of that window, someone else controlled where Elsevier's traffic went."
        https://www.cloudskope.com/breaches/elsevier-lapsus-domain-hijack-2026
        https://www.helpnetsecurity.com/2026/09/22/elsevier-domains-hijack-lapsus/

      General News

      • August 2026 Infostealer Trend Report
        "This report summarizes the distribution channels, number of Infostealers, number of detections, and companies disguised as targets by new Infostealers collected during the month of August 2026. It is based on data from AhnLab SEcurity intelligence Center (ASEC), AhnLab product diagnostic logs, automated data collection systems, email honeypot systems, and automated C2 analysis systems."
        https://asec.ahnlab.com/en/95519/
      • Disrupting EvilTokens: The AI Chatbot Built For Cybercrime
        "Microsoft has disrupted EvilTokens, a powerful cybercrime platform that used AI at every step of the attack chain—from compromising email accounts to designing intricate roadmaps for financial fraud and scams. While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed. The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action. In short, AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible."
        https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/
        https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/
        https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
        https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
        https://therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens
        https://cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/
        https://www.theregister.com/security/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-websites/5298317
      • Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
        "The debate around AI governance heated up this past week as AI experts warned that the growing number of rogue AI agents and instances of misaligned behavior are merely a preface to worse threats in the future. On Sept. 12, Anthropic CEO Dario Amodei warned in a widely read column that AI could soon slip the harness of human control if development is left unchecked. Within a few days, Microsoft delivered a Humanist AI Code of Conduct (read: manifesto) pledging human-centered development, and Google DeepMind's CEO agreed in principle in a post on X to the calls for more controls. Although Anthropic, OpenAI, and x.AI have all also suggested tighter government regulations for the technology, President Donald Trump dismissed the idea, suggesting that winning the AI competition with China is more important, reportedly saying, "Whoever wins AI, wins.""
        https://www.darkreading.com/cyber-risk/rogue-incidents-debate-ai-safety-gets-real

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 0bcdd868-7318-4640-a6ea-4e83352450b0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบแคมเปญ LastPass ปลอม แพร่มัลแวร์ Rapuncel ขโมยข้อมูลและปิดการทำงาน Antivirus และ EDR

      พบแคมเปญ LastPass ปลอม แพร่มัลแวร์ Rapuncel ขโมยข้อมู.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b23af663-4068-4027-a555-0b4cb20494aa-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ShinyHunters เจาะและเปลี่ยนหน้า Leak Site ของ Clop Ransomware บน Dark Web

      ShinyHunters เจาะและเปลี่ยนหน้า Leak Site ของ Clop Ransomware บน Dark Web.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f7ef0fb6-8ca4-4958-93f3-170e49408b82-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ ChainScript ที่ซ่อนเซิร์ฟเวอร์ควบคุมสั่งการผ่านสมาร์ตคอนแทรกต์บนเครือข่ายบล็อกเชน

      พบมัลแวร์ ChainScript ที่ซ่อนเซิร์ฟเวอร์ควบคุม สั.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b89f76bb-01aa-4a3b-bb2b-472f18b35ab8-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 22 September 2026

      New Tooling

      • Gopass: Open-Source Command-Line Password Manager For Teams
        "Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager. Out of the box, Gopass encrypts each secret with GPG and keeps the store in a git repository. Git gives a team a record of every change and a way to sync one store across laptops and servers. Users who want different tools can switch encryption to age, switch storage to fossil, or drop versioning with the --storage=fs flag."
        https://www.helpnetsecurity.com/2026/09/21/gopass-open-source-password-manager/
        https://github.com/gopasspw/gopass

      Vulnerabilities

      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog
      • No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security
        "Most security research starts with an attacker. Ours kept finding trouble without one. In August, we gave our R&D teams two days and a single prompt: build the demo customers would ask to see twice. Hackathons like this one are a fixture of how we work. In a field moving as fast as agentic AI security, two unscheduled days are often where the ideas that end up mattering first show up."
        https://blog.checkpoint.com/ai-security/no-attacker-required-what-a-two-day-hackathon-taught-us-about-agent-security/
      • Intent Injection Attacks Are a New Worry For AI-Native 6G Networks
        "Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have moved to the forefront. Researchers at the University of Ottawa and Nokia Bell Labs argue that this abstraction gives attackers new openings, and it tests two machine-learning detectors against one of them. The authors call that threat adversarial intent injection: hiding malicious instructions among legitimate ones. They evaluated their detectors on 1,100 intents they constructed, partly with a large language model’s help, so the reported figures describe performance on that dataset."
        https://www.helpnetsecurity.com/2026/09/21/6g-intent-injection-attacks/
        https://arxiv.org/pdf/2609.12144

      Malware

      • TASK#STOMP: PowerShell Backdoor For Document Theft And Remote Access
        "Securonix Threat Research analyzed a script-driven Windows execution chain that begins with a desktop VBScript and deploys a redundant persistence framework under %LOCALAPPDATA%\WinDefendSvc. The sample creates four scheduled tasks from XML definitions, places msdiag.vbs in the user Startup folder, terminates existing loader instances, backdates core artifacts, launches two hidden PowerShell modules, compiles C# code at runtime through the legitimate .NET compiler, opens a specific web page in Chrome, and executes a cleanup batch file."
        https://www.securonix.com/blog/task-stomp-powershell-backdoor-document-theft-remote-access
        https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html
        https://www.helpnetsecurity.com/2026/09/21/taskstomp-windows-backdoor/
      • Be Alert: Targeted Attacks On Prominent Rustaceans
        "We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard)."
        https://blog.rust-lang.org/2026/09/17/targeted-attacks/
        https://www.theregister.com/security/2026/09/21/rustaceans-warned-of-job-interviews-with-a-malicious-payload/5297690
        https://www.securityweek.com/rust-team-members-and-popular-crate-owners-targeted-via-video-calls/
        https://www.helpnetsecurity.com/2026/09/21/north-korean-hackers-contagious-interview-defenses/
      • Exvicy: A Copycat Of The ErrTraffic Malware Distribution Framework
        "This article details how TDR pivoted from a forum advertisement to identify confirmed operator infrastructure, analyzes the Exvicy infection chain, and provides code evidence establishing that this emerging MaaS is a direct copycat of the adopted ErrTraffic framework. Sekoia's TDR team discovered Exvicy, a new ClickFix malware distribution framework, from a single forum screenshot all the way to its operator's live infrastructure."
        https://www.sekoia.com/blog/exvicy-a-copycat-of-the-errtraffic-malware-distribution-framework
        https://www.infosecurity-magazine.com/news/exvicy-clickfix-framework/
      • GHAPPIER - One Loader, Sixty-Five Repositories, Twenty-Two Accounts: An Unreported Loader Family Beside DPRK's PolinRider Campaign
        "CloudSEK researchers uncovered GHAPPIER, a previously unreported loader operation spanning at least 65 public repositories, 73 infected files and 22 accounts. The investigation began with a compromised legitimate npm package whose malicious release carried valid provenance through trusted publishing. The report maps the wider infrastructure, links parts of the activity to the PolinRider campaign, and details indicators, attack flow and defensive actions."
        https://www.cloudsek.com/blog/ghappier-malware-loader-npm-supply-chain-attack
        https://www.infosecurity-magazine.com/news/attackers-abuse-npm-trusted/
      • The Fake Sites Using a Cheap Toolkit To Sell $2,000 AI Subscriptions
        "We found more than 100 subscription websites linked through the same toolkit and closely related developer details. Some impersonate existing products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. Another uses the name of Omegle, the chat service that shut down in 2023. Others promote unfamiliar brands with little verifiable information about who operates them."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/the-fake-sites-using-a-cheap-toolkit-to-sell-2000-ai-subscriptions
      • Group Policy Hijacked: PAYLOAD Ransomware Weaponizes Active Directory GPO
        "In April 2026, we at Kaspersky’s Global Emergency Response Team (GERT) responded to a security incident at a manufacturing organization in the Middle East. The threat actor obtained domain admin-equivalent control of the organization’s Active Directory environment and authored a malicious Group Policy Object (GPO) named PAYLOAD, linking it at the domain root. Through that single object, the actor delivered ransom notes, hijacked the desktop wallpaper and lock screen, enforced a logon banner, and disabled the local administrator account across every domain-joined Windows workstation — all without dropping a ransomware binary or encrypting any data."
        https://securelist.com/tr/payload-ransomware-via-group-policy/121335/
      • Vidar Adds Virtual Machine And Custom Stream Ciphers For String Obfuscation
        "Vidar is an information stealer that was first observed in 2018. Across its iterations, Vidar has continued to improve its string obfuscation to make detection and analysis more difficult by changing deobfuscation algorithms, constants, and primitives. From May through early September 2026, Zscaler ThreatLabz tracked Vidar’s string obfuscation as it evolved from basic XOR to ChaCha20, and more recently, to a custom virtual machine (VM), which is executed via a lightweight bytecode interpreter that is combined with a custom stream cipher that changes with each build. In this blog post, ThreatLabz covers Vidar’s string obfuscation methods from version 2.0 to the latest version 3.3."
        https://www.zscaler.com/blogs/security-research/vidar-adds-virtual-machine-and-custom-stream-ciphers-string-obfuscation
      • ChainScript: Tracing a Node.js RAT Through The Blockchain
        "Blackpoint’s Adversary Pursuit Group (APG) identified and analyzed a previously unnamed Node.js remote access trojan, now being tracked as ChainScript. The malware was uncovered while investigating ClickFix activity that led to the execution of a malicious Windows Installer disguised as Spotify software. Once executed, the MSI deployed its own Node.js runtime and launched a JavaScript agent through hidden PowerShell and VBScript stages. The running agent then established persistence in the user profile."
        https://blackpointcyber.com/blog/chainscript-tracing-a-nodejs-rat-across-the-blockchain/
        https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html
        https://securityaffairs.com/199471/malware/chainscript-the-rat-that-hides-its-command-server-inside-a-blockchain-contract.html
      • Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface On Victim With No Crypto Ties
        "Throughout 2026, the financially motivated DPRK state-sponsored Lazarus subgroup TraderTraitor (aka UNC4899, PUKCHONG, Jade Sleet) has engaged in campaigns targeting entities involved in cryptocurrency trading, including a high-profile attack disclosed in April where USD 292 million was stolen from KelpDAO through a compromise of LayerZero. KelpDAO is a decentralized finance (DeFi) protocol that supports restaking Ethereum; LayerZero Labs provides services with the capability to exchange cryptocurrency across different blockchain platforms."
        https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/
        https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html
      • Russia Reports Thousands Of Cyberattacks On Election Infrastructure During Vote
        "Russian authorities said they repelled thousands of cyberattacks targeting online voting systems and other digital infrastructure during the country's three-day parliamentary election. According to Deputy Digital Development Minister Oleg Kachanov, Russia detected and blocked about 2,000 cyberattacks and other attempts to disrupt its federal online voting platform and e-government systems. Kachanov said Sunday that the incidents caused no service disruptions and that Russia’s newly deployed election administration system, Vybory 2.0, continued operating normally."
        https://therecord.media/russia-reports-cyberattacks-during-election

      Breaches/Hacks/Leaks

      • BigCommerce Alerts Merchants Of Data Breach Linked To Ribon Apps
        "Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. The cloud-based Software-as-a-Service (SaaS) ecommerce platform confirmed the credential compromise on September 17 and immediately removed the apps to protect its customers. UK-based online spirits vendor Master of Malt is one of the BigCommerce customers that received the notification. The retailer said the attacker accessed shopper information."
        https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/
      • Belgian Table Tennis, Gymnastics Federations Hit By Cyberattacks
        "Belgium’s national table tennis federation and its French-speaking branch are investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members and users. Jean-Michel Mureau, president of the French-speaking Association Francophone de Tennis de Table (AFTT), confirmed the attack over the weekend and said the Royal Belgian Table Tennis Federation (FRBTT) had also been affected. “I can confirm that there was indeed an attack,” Mureau said in a statement. “We have tasked our IT department with investigating to determine exactly what data was compromised.”"
        https://therecord.media/belgium-table-tennis-cyberattack
      • Cyberattack Hits University Of Munich, Potentially Exposing Student Financial Data
        "Germany’s Ludwig Maximilian University of Munich is investigating a cyberattack in which an unknown hacker accessed a system containing sensitive student information, including potential health insurance and financial aid data. The university, commonly known as LMU Munich, said Saturday that an attacker accessed enrollment data stored on one of its IT systems. “Currently, we must assume that this data were in fact retrieved,” the university said, adding that the investigation into the incident is ongoing."
        https://therecord.media/cyberattack-hits-university-of-munich-potentially-exposing-data
      • Colorado Water Utilities Hit By Cyberattacks Targeting OT Systems
        "Hackers targeted operational technology (OT) systems at two private water utilities in Colorado in late August, apparently attempting to cause disruptions. Few technical details are available, but it seems the attackers targeted industrial control systems (ICS) at the water utilities, which serve fewer than 200 people. A spokesperson for Colorado Governor Jared Polis told The Denver Post [paywalled] that the attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. However, the disruptions were brief and did not affect water services or public safety."
        https://www.securityweek.com/colorado-water-utilities-hit-by-cyberattacks-targeting-ot-systems/
        https://securityaffairs.com/199480/ics-scada/foreign-hackers-target-two-colorado-water-utilities.html

      General News

      • Know What Was Tested Before Your SAP ECC Migration Goes Live
        "In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls projects more often than budget, and what the first ninety days of a phased migration involve. It also looks at staff who hold years of knowledge about the old system, and a Central American project that passed every quality gate but still had a difficult go live."
        https://www.helpnetsecurity.com/2026/09/21/guilherme-joventino-mignow-sap-ecc-migration/
      • AI Compliance Issues Hit 2 In 5 Large Companies, And Legacy Workflows Are a Big Factor
        "Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contributed to 84 percent of the incidents. The researchers trace the exposure to workflows designed around people. Approvals, handoffs, and manual exceptions exist because a person was expected to handle each step. When a company drops AI into that design, checks sit at the wrong point, work changes hands with nothing written down, and the audit record cannot show how a decision was reached. A CISO who has to explain an AI-assisted decision to an auditor may find the evidence was never captured."
        https://www.helpnetsecurity.com/2026/09/21/ai-compliance-issues-research/
      • Anthropic-Linked CVEs Pile Up, Attackers Mostly Shrug
        "Despite the concern that advanced AI models’ bug-hunting prowess will lead to attackers exploiting more newly uncovered CVEs, fewer than 0.5 percent of the vulnerabilities linked to Anthropic or Project Glasswing are being batttered in the wild, according to VulnCheck security researcher Patrick Garrity. Garrity began tracking CVEs attributed to Project Glasswing, Anthropic’s initiative to give select partners access to its Claude Mythos Preview model, shortly after the AI company announced the program in April."
        https://www.theregister.com/security/2026/09/21/anthropic-linked-cves-pile-up-attackers-mostly-shrug/5298018
      • CISO Conversations: Noopur Davis – The Accidental Global CISO At Comcast
        "Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be. Comcast, founded in Tupelo, Mississippi, in 1963, is now a global media and technology company headquartered in Philadelphia, Pennsylvania. It has offices in North America, Europe, Asia, and Australia, and a global workforce of around 180,000 people. Noopur Davis is the organization’s Global CISO, leading multiple security teams distributed around the world and a total headcount of around 1,500 security team members."
        https://www.securityweek.com/ciso-conversations-noopur-davis-the-accidental-global-ciso-at-comcast/
      • The Target Is No Longer The Model. It’s The Agent.
        "I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guide to a new attack surface. In my previous piece, I explained how MITRE ATLAS catalogs threats to AI. Here, I take the next step: I map that research onto ATLAS. What emerges is a complete kill chain, and the target is no longer the model. It’s the agent."
        https://securityaffairs.com/199454/ai/the-target-is-no-longer-the-model-its-the-agent.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 5681b576-c020-41e2-80be-72cd9efb0fc5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 21 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fe642e6e-d04a-4e31-8ae3-7a866bc6cd63-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 18 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2025-39964 Linux Kernel Race Condition Vulnerability
      • CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
      • CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 642cbaf6-39c2-4f35-a1ca-346881ca1e42-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน SolarWinds Access Rights Manager เสี่ยงถูกรันคำสั่งโดยไม่ต้องยืนยันตัวตน

      ช่องโหว่ใน SolarWinds Access Rights Manager เสี่ยงถูกรันคำสั่ง.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d49e701b-def6-47e2-a858-0e831b1bc3d9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • นักวิจัยเผย AI ช่วยเร่งพัฒนา Exploit ช่องโหว่ Discourse จนยึดบัญชี OpenAI Staff ได้ผ่านระบบ SSO

      นักวิจัยเผย AI ช่วยเร่งพัฒนา Exploit ช่องโหว่ Discourse.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f3b59166-76bc-4856-b169-47a6f3d848a8-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ค้นพบแนวคิดการโจมตีเทคนิค "BragJack" ที่ใช้ควบคุมผู้ช่วย AI บนเบราว์เซอร์ผ่าน Extension

      ค้นพบแนวคิดการโจมตีเทคนิค BragJack ที่ใช้ควบคุ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dfcf80ca-c59d-4c58-8e6c-6556be8ba002-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 21 September 2026

      Vulnerabilities

      • New Check Point Flaw Lets Hackers Execute Code With Root Privileges
        "Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. Tracked as CVE-2026-91843, this flaw stems from a stack-based buffer overflow weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events. The security issue also affects the company's Log Server, a dedicated server that collects and stores logs generated by Check Point firewalls."
        https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/
        https://thehackernews.com/2026/09/critical-check-point-management-server.html
        https://securityaffairs.com/199279/security/check-point-fixes-critical-cve-2026-91843-allowing-root-code-execution.html
      • Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
        "Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network," Microsoft said in a Thursday advisory."
        https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
        https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889
      • Critical Orkes Conductor Vulnerability Exploited In Attacks
        "A critical-severity vulnerability in Orkes Conductor that can be exploited without authentication has been in attackers’ crosshairs for at least a month. Conductor is an open source unified enterprise framework that allows organizations to orchestrate microservices, workflows, and AI agents. Tracked as CVE-2026-58138 (CVSS score of 9.8), the critical bug is described as a remote code execution issue exploitable via inline workflow definitions submitted to the workflow API endpoint."
        https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/
        https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
      • Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read And Modify MacOS Host Files
        "Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions 0.28.0 up to but not including 0.42.0 on macOS, and was fixed in 0.42.0 on September 7."
        https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
      • SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
        "SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. "SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability," SolarWinds said in an advisory released on September 17, 2026. "The issue stems from a hard-coded static key.""
        https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-39964 Linux Kernel Race Condition Vulnerability
        CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog
        https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
        https://securityaffairs.com/199430/security/u-s-cisa-adds-linux-kernel-flaws-to-its-known-exploited-vulnerabilities-catalog-2.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog
      • A Quartet Of Linux Local Root Vulns: DirtyAH6, PPPoEject, TUNderflow, And DiagSpill
        "This will be shorter than usual because a) I’m under a time crunch and b) we are covering 4 vulnerabilities at once. These were discovered by combining the graph-based tracking of security-relevant objects/properties used in CIFSwitch with the tooling to enable agents to think ‘geometrically’ about the memory state, as seen in OVSwrap. See those posts’ Background sections for more info. The harness design is captured, in broad strokes, in Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More), though it’s evolved considerably since."
        https://heyitsas.im/posts/lpe-quartet/
        https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html
      • Click2Shell: Preauth WordPress Core Theme Preview Injection To RCE Chain
        "One month after XSS2Shell, we returned to WordPress Core looking for another pre-authentication RCE chain. This time there was no preauth XSS in Core. Instead we found a specially crafted preview link made WordPress install an attacker-selected catalog theme and load its PHP before activation. Chained with a real flaw in any theme, we manage to convince WordPress to execute attacker-supplied PHP code after one visit to attacker site."
        https://pwn.ai/blog/click2shell
        https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html
      • Hacking OpenAI
        "On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts. With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors. To prove we had in fact gained the access we believed without allowing ourselves to learn any sensitive information, we used the employee’s Codex to open a PR #1186742 in OpenAI’s internal monorepo openai/openai."
        https://www.hacktron.ai/blog/hacking-openai
        https://heif-heist.com/
        https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
        https://www.theregister.com/security/2026/09/18/researchers-used-claude-to-hack-openai-employees-chatgpt-accounts/5297517
        https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/
        https://cyberscoop.com/hacktron-ai-heif-heist-vulnerability/
        https://securityaffairs.com/199378/ai/ai-helps-hackers-hijack-openai-staff-accounts-through-a-forum.html
      • A Vault With a Heap-View: The Uncomfortable Space Between AgentCore Harness And Identity
        "Unit 42 researchers have identified an issue where using default configurations in Amazon Web Services (AWS) AgentCore Harness could allow attackers to steer an agent's actions through prompt injection to exfiltrate plaintext credentials managed by AgentCore Identity. To reach that finding, we examined two of the harness's many integrations:"
        https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/
      • Microsoft Patches 18 Vulnerabilities In AI, Cloud Products
        "Microsoft released patches for 18 vulnerabilities on Thursday, spanning its Azure cloud portfolio and Copilot-branded AI products. Elevation of privilege flaws made up the bulk of the disclosures, affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot. Several information disclosure vulnerabilities were addressed in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning. A single spoofing vulnerability was patched in Azure Portal."
        https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/
      • Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
        "Cybersecurity firms Check Point, Kaspersky, and Tanium have each patched severe vulnerabilities in their products, including ones that can be exploited for remote code execution. Check Point has informed customers about a critical vulnerability affecting Security Management and Log Server products. The flaw, CVE-2026-91843, can be exploited by an unauthenticated attacker “to remotely execute arbitrary code with root privileges through the login process.”"
        https://www.securityweek.com/check-point-kaspersky-tanium-patch-product-vulnerabilities/
      • Escaping The OpenAI Codex Sandbox, Twice
        "We found two ways out of the OpenAI Codex sandbox and reported both to OpenAI on August 12, 2026. Both were fixed inside of eight days. The first is in the open-source Codex CLI. One extra line in a patch hands the patch tool write access to the whole disk, in the normal agent mode, with no approval prompt. We call it Overpatch. The second is in the JavaScript tool that Codex Desktop installs. The sandbox worked, but the secret that told trusted code from untrusted code was sitting in memory the untrusted code could read. We call it Heapjack. It runs at read-only, where the agent supposedly can’t write anything, and it ends with unsandboxed command execution."
        https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/
        https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/

      Malware

      • Private HTS Programs That Spread Ransomware
        "AhnLab SEcurity intelligence Center (ASEC) recently identified a case in which ransomware was distributed through a private home trading system (HTS). The HTS program used to distribute the ransomware is called “UBP Asset” and has long been exploited in online investment scams. Given that a photo of the same HTS program was also found in a blog post by a law firm in Korea published in September 2025, it appears that investment fraud organizations have recently been distributing ransomware to their victims."
        https://asec.ahnlab.com/en/95469/
      • One Kit, Forty Companies: How a Malware-As-a-Service Platform Used GitHub As a Distribution Network For Its Campaign
        "LastPass Threat Intelligence, Mitigation, and Escalation (TIME) Team, in partnership with Delphos, identified and disrupted a multi-stage malware delivery campaign impersonating at least 40 companies on GitHub. The payload it delivered survived controls that were built to stop exactly this, with a Microsoft Windows Hardware Compatibility Publisher chain signature and a clean VirusTotal score. LastPass is internally tracking the infostealer as Rapuncel."
        https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer
        https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/
      • Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM
        "Settra is a newer ransomware variant that was first observed in June 2026. Based on public reporting, the attackers behind the variant have targeted virtual private networks (VPNs) or used compromised credentials for initial access. Huntress has investigated two Settra ransomware incidents since July. Although the initial access method could not be confirmed, both attacks used ransomware executables named after the victim organization's domain and followed a highly similar operational pattern."
        https://www.huntress.com/blog/new-settra-ransomware-variant
        https://www.infosecurity-magazine.com/news/settra-ransomware-retail/
      • Fake Parcel Delivery Messages Steal Your Card And Bank Details
        "Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands. The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial information."
        https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details
      • WeaselBiscuit Stealer Spreads Via 13 Npm Packages To Harvest Chrome Extension Storage
        "Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and OtterCookie. "It's smaller, lighter, and stripped down, with many of the heavier functions removed entirely," security researcher Paul McCarty (aka 6mile) said."
        https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
      • North Korean Hackers Infect Thousands Of Devices Across 100 Countries As Part Of ‘WaterPlum’ Campaign
        "More than $10.5 million has been stolen by North Korean hackers targeting job seekers as part of a long-running cyber campaign to infiltrate tech companies and fill Pyongyang’s coffers with illicitly gained funds. The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies."
        https://therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme
        https://www.ic3.gov/CSA/2026/260918.pdf
        https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/
        https://cyberscoop.com/north-korea-waterplum-job-seeker-crypto-attacks/
        https://www.theregister.com/security/2026/09/18/north-koreas-fake-job-interviews-infected-30000-devices/5297461
      • Silent Push Tracks a Mass Phishing Operation Through Fast Flux
        "While the “fast flux” technique of rapidly rotating a domain’s DNS records across many IP addresses and networks to avoid detection is not new, it has become more sophisticated and easier for threat actors to use in phishing campaigns and other malicious activities. Going deeper into our research on fast flux, we became a customer to see its inner workings. We identified a large, active global phishing operation from a single query in our platform. This blog outlines some of the phishing campaign’s infrastructure; its structure is quite effective, making it nearly impossible for most defenders to detect."
        https://www.silentpush.com/blog/fast-flux-phishing/
      • Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
        "Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed by OpenAI, Anthropic, and Meta. According to the Journal, the model gained access to a protected system after repeatedly guessing its password. Two other cases related to the model finding credentials in a public repository, allowing it to obtain unauthorized access to protected systems."
        https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html
        https://securityaffairs.com/199392/ai/google-gemini-also-broke-out-of-its-test-environment.html
      • TanStack Supply Chain Attack Analysis
        "Every hack happens in a context where humans, business, technology, or society as a whole is evolving. What stings for CrowdSec is that many of us come from red-team pentesting backgrounds, have worked in cyber for decades, and have adopted a “cybersec” muscle memory in our daily work. So being caught leaking code is painful. CrowdSec is doing much better after we found deeper PMF (Product-Market Fit) for our data, and our low-touch SaaS model started to click with users. The team is a bit smaller because we had to keep costs under control in an environment where access to funds was more limited than before."
        https://www.crowdsec.net/blog/tanstack-supply-chain-attack-analysis
        https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
      • Npm ‘btree’ Malware Campaign Affects Millions Of Downloads, No Need For Install Script
        "An ongoing npm supply chain campaign is using a malicious package, indexed-btree, that mimics the legitimate sorted-btree library — but instead of a preinstall or postinstall script, its malware trigger is buried inside the package’s own prototype method, firing the moment the library is used. The malware fingerprints hosts, exfiltrates data via Slack and Telegram, and uses an Ethereum smart contract as a resilient C2 channel. Checkmarx Zero breaks down the technique, the IOCs, and why runtime — not just install-time — analysis is now essential."
        https://checkmarx.com/zero-post/npm-btree-malware-campaign-affects-millions-of-downloads-no-need-for-install-script/
        https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/

      Breaches/Hacks/Leaks

      • ShinyHunters Hacks Clop Leak Site, Threatens To Extort Ransomware Gang
        "The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop's site. The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter's own data leak site. "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time," read the uploaded file."
        https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/

      General News

      • August 2026 Threat Trend Report On APT Groups
        "The August 2026 APT Threat Trends report summarizes attack cases in which state-sponsored threat actors combined attacks involving open-source supply chain compromises, the use of generative AI, the exploitation of legitimate cloud services, job scams, and the exploitation of zero-day vulnerabilities. A key finding is the use of GitHub, GitLab, OneDrive, Telegram, Discord, Google Sheets, and blockchain networks as C2 (Command and Control) channels, payload delivery mechanisms, and information exfiltration channels."
        https://asec.ahnlab.com/en/95478/
      • AI Governance Has Entered Its Next Phase: Closing The Confidence Gap
        "Most large organizations have established the foundations of responsible AI. Policies are in place. Oversight committees have been formed. Reviews, controls and human oversight are becoming part of the enterprise operating model. But as AI adoption accelerates and autonomous agents begin taking actions across business processes, a more consequential question is emerging … Can governance keep pace?"
        https://www.ey.com/en_us/insights/assurance/ai-governance-has-entered-its-next-phase-closing-the-confidence-gap
        https://www.darkreading.com/cyberattacks-data-breaches/ey-survey-autonomous-ai-implementation-outpaces-oversight
      • MFA Won't Save You From OAuth Consent Abuse
        "Attackers can gain persistent software-as-a-service (SaaS) access through a single convincing consent prompt, without needing passwords or malware. Security teams have long treated multifactor authentication (MFA) as a strong signal that an account is protected. That thinking is understandable, but it's incomplete. MFA secures authentication. It does not control what users are allowed to authorize after they log in."
        https://www.darkreading.com/vulnerabilities-threats/mfa-oauth-consent-abuse
      • Bots With Good Manners Are Better At Fooling People On Social Media
        "Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a social media setting. Overall, people caught just 40% of the bots placed in front of them. The bots that slipped by most often weren’t loud or aggressive. They were positive, friendly, and logical-sounding, the exact traits that make a stranger’s comment feel safe to trust."
        https://www.helpnetsecurity.com/2026/09/18/social-media-bot-detection-study/
      • Abandoned IoT Apps Keep Sending Sensitive Data To Broken Servers
        "Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned Android IoT apps and found that nearly three in four contained software dependencies associated with documented vulnerabilities."
        https://www.helpnetsecurity.com/2026/09/18/abandoned-iot-apps-data-security-risks/
        https://arxiv.org/pdf/2609.14798
      • Hardcoded MCP Credentials Found In Public GitHub Files
        "Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal, potentially exposing credentials for connected services and systems."
        https://www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/
      • 98% Of Fraudulent Hires Have Company Credentials By The Time They’re Caught
        "A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO of HYPR. “Human intuition is not a security control. Sceptics might point to low reported numbers, but the lack of purpose-built verification technology means the industry is simply blind to the problem; there are vastly more fraudulent workers embedded in organizations than current data reflects.”"
        https://www.helpnetsecurity.com/2026/09/18/hypr-hiring-fraud-detection-report/
      • What The NATO Threat Landscape Report 2026 Reveals About Trusted Access And Cyber Risk
        "A cybersecurity report written for a military alliance may seem distant from the daily work of defending business networks. But the 2026 NATO Threat Landscape Report includes universally applicable findings about how modern attacks move through interconnected environments, trusted access and third-party relationships. The report argues that as NATO hardens its core infrastructure, adversaries increasingly look for weaker points in the surrounding ecosystem: cloud providers, software vendors, contractors, logistics partners, and other organizations with legitimate access. That framing should be familiar to any security team. Few organizations operate inside a clean perimeter anymore."
        https://blog.barracuda.com/2026/09/17/nato-threat-landscape-report-trusted-access-risk
        https://socradar.io/wp-content/uploads/2026/07/NATO-Threat-Landscape-Report-2026.pdf
      • Nations Take Action On North Korean IT Workers After UN Report
        "Multiple countries have taken legal action against North Koreans or local handlers following a report from the United Nations about Pyongyang’s illicit IT worker scheme. The Multilateral Sanctions Monitoring Team (MSMT) — a U.S.-led international committee tasked with tracking compliance of UN sanctions on the Democratic People's Republic of Korea (DPRK) — released a new report on Wednesday spotlighting the thousands of North Korean nationals who work outside of the country in various industries."
        https://therecord.media/nations-take-action-on-north-korean-it-worker-schemes
        https://msmt.info/Publications/detail/MSMT Report/4232
      • FBI: Fake Cop And Government Impersonation Scams Cost Victims $1.6B
        "Scammers impersonating law enforcement or government officials have cost victims more than $1.6 billion since January 2025, the FBI reports. The FBI’s Internet Crime Complaint Center (IC3) received close to 61,000 complaints of this type between January 2025 and July 2026, putting the average per-complaint loss at more than $26,000. The most common type of scam is one involving criminals convincing targets to pay a sum of money to remove charges the fraudsters claim were filed against them."
        https://www.theregister.com/cyber-crime/2026/09/18/fbi-fake-cop-and-government-impersonation-scams-cost-victims-16b/5297499
        https://www.ic3.gov/PSA/2026/PSA260917
      • Early Scattered Spider Member Pleads Guilty To Cybercrime Spree
        "Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday. Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy and aggravated identity theft. His guilty plea wasn’t shared publicly until prosecutors filed an order of forfeiture this week seeking proceeds from Elbadawy’s criminal activities."
        https://cyberscoop.com/scattered-spider-member-guilty-ahmed-elbadawy/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 3a845489-d43a-4060-a468-2cf2f21975c4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 17 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-260-01 Bransys ELD
      • ICSA-26-260-02 Mitsubishi Electric GX Works3
      • ICSA-26-260-03 Hitachi Energy FACTS Control Platform (FCP)
      • ICSA-26-260-04 Schneider Electric Modicon M340 Controller and Communication Modules
      • ICSA-26-260-05 Schneider Electric NetBotz 5 750/755
      • ICSA-26-260-06 ABB Ability Edgenius
      • ICSA-26-260-07 Schneider Electric PowerChute Serial Shutdown
      • ICSA-26-211-07 Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 90e9ba8d-68b8-48d7-806f-321625b1d089-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 15 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      ICSA-26-258-01 Digital Watchdog VMAX, DVR and NVR Product Lineups
      ICSA-26-258-02 Wärtsilä FOS-Onboard
      ICSA-26-258-03 mySCADA myPRO Manager
      ICSA-26-258-04 Schneider Electric SCADAPack x70 Products
      ICSA-26-258-05 Siemens Reyrolle 7SR5
      ICSA-26-258-06 Siemens Mendix SAML
      ICSA-26-258-07 Siemens Teamcenter
      ICSA-26-258-08 CareCam CM2507

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 950163a1-2cf2-4275-8711-b0f70b9b986e-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT