NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,506
    • กระทู้ 2,507
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • Cyber Threat Intelligence 26 August 2026

      Healthcare Sector

      • MyChart Portal Phishing Scams Target Patients Nationwide
        "Dozens of U.S. healthcare systems are warning patients about potential email phishing, text and phone scams involving their MyChart patient portals. Electronic health record vendor Epic, the maker of MyChart, has also issued a public warning about the threats. The phishing campaigns involve fraudsters using the MyChart name and logo to appear legitimate in their scam messages. The communications promise the patients a "2026 MyChart Senior Health Package," Medicare wellness benefits, a free health kit or other gifts when recipients "claim their reward" by clicking a link, confirming an address or providing other personal information."
        https://www.bankinfosecurity.com/mychart-portal-phishing-scams-target-patients-nationwide-a-32651

      Industrial Sector

      • Siemens SIMATIC IoT2050 Advanced
        "SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03
      • Ebyte NE2-D11
        "Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
      • Zoneminder
        "Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-02
      • PayRange API
        "Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-04
      • FURUNO FA-50 Class B AIS Transponder
        "Successful exploitation of these vulnerabilities could allow an attacker to alter device settings."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07
      • Threat Landscape For Industrial Automation Systems. Q2 2026
        "In this section, we examine the most significant changes to indicators over the quarter, broken down by region and industry. Further diagrams can be found in the relevant chapters of the “Statistics across all threats” section."
        https://ics-cert.kaspersky.com/publications/reports/2026/08/25/threat-landscape-for-industrial-automation-systems-q2-2026/
      • Rently Smart Home
        "Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01
      • Bendix EC80 Brake ECU
        "Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05

      New Tooling

      • HOL Guard: Open-Source Antivirus For AI Agents
        "HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds. Your files are never uploaded, and the whole thing works with no internet connection. The people exposed here are anyone using Claude Code, Cursor, Codex, Gemini CLI, OpenCode, Hermes, or OpenClaw."
        https://www.helpnetsecurity.com/2026/08/25/hol-guard-open-source-antivirus-ai-agents/
        https://github.com/hashgraph-online/hol-guard

      Vulnerabilities

      • Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute In Edit Mode
        "Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked as CVE-2026-75149, is a code injection issue affecting versions prior to 0.23.15. VulnCheck's CVE Numbering Authority (CNA) record assigns it a CVSS v4 score of 8.7 and a CVSS v3.1 score of 8.8, with user interaction required and no attacker authentication required."
        https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-60004 Gitea Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog
      • Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning
        "A vulnerability in NVIDIA NemoClaw, a tool that deploys the OpenClaw AI agent, can hand an attacker full, unauthenticated control over the local model server that powers the agent and silently plant instructions inside the model. A single visit to an attacker-controlled webpage is all it takes to give the attacker these capabilities. NemoClaw deploys inside NVIDIA OpenShell sandboxes with local inference via Ollama. Oasis Security discovered the vulnerability as part of ongoing research into non-human identity and AI agent risks."
        https://www.cyera.com/research/nemoclaw-one-website-visit-to-hijack-your-ai-agent
        https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html
        https://www.darkreading.com/cyber-risk/nemo-claw-networking-llm-poisoning-openclaw
      • Vulnerability In GNU Wget Software
        "CERT Polska has received a report about vulnerability in GNU wget software and participated in coordination of its disclosure. The vulnerability CVE-2026-16599: GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation."
        https://cert.pl/en/posts/2026/08/CVE-2026-16599/

      Malware

      • ClickFix Phishing Pages Discovered In 24 Npm Packages
        "The OX Research team is tracking a fake Cloudflare campaign being distributed on the npm registry: Our research found a total of 24 packages containing the same HTML page, with each package usually reaching between 50-300 weekly downloads before it gets removed. But downloading and installing such a package to a machine doesn’t do any harm, so why do we bother researching it? While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware."
        https://www.ox.security/blog/research-clickfix-phishing-npm-packages/
        https://thehackernews.com/2026/08/24-npm-packages-abuse-unpkg-mirrors-to.html
        https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/
      • Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
        "The SOCRadar Threat Research Unit (STRU) has conducted an “inside-out” analysis of AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) ecosystem specifically engineered to disable Apple’s Activation Lock on stolen devices. Operating as a credit-metered platform, AnonyMousKIT automates credential harvesting through a sophisticated multi-channel pipeline – integrating email, SMS, and WhatsApp with advanced conversational AI agents to conduct AI-driven Automated Social Engineering (voice phishing) calls. By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mimic “Apple Support,” basic coding errors exposed production logs and operator rosters."
        https://socradar.io/blog/anonymouskit-ai-phaas-supply-chain/
        https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/
      • Massive DDoS Attack Disrupts Norway’s Government Digital Services
        "A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector. The attack started at 03.38 CEST on Monday and has targeted the infrastructure supporting services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta. Digdir operates Norway’s shared digital government infrastructure, including public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies."
        https://www.bleepingcomputer.com/news/security/massive-ddos-attack-disrupts-norways-government-digital-services/
        https://therecord.media/norway-cyberattack-ddos-government
        https://securityaffairs.com/197826/cyber-warfare-2/norway-s-digital-government-infrastructure-hit-by-a-new-ddos-attack.html
      • Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations
        "Check Point has identified and blocked a large-scale email phishing campaign using fraudulent financial hardship and debt-relief offers to manipulate recipients into calling attacker-controlled phone numbers. Over the past 14 days, Check Point observed approximately 24,700 emails associated with the campaign targeting users across more than 9,000 organizations, demonstrating both the scale of the operation and the continued evolution of phishing beyond malicious links and attachments. The campaign underscores a growing enterprise risk: phishing no longer needs an obvious malicious link, attachment, or spoofed sender to be effective. Attackers are turning routine-looking email into the entry point for trusted conversations that take users beyond traditional controls."
        https://blog.checkpoint.com/securing-user-and-access/check-point-blocks-large-scale-debt-relief-email-phishing-campaign-targeting-more-than-9000-organizations/
      • An Invisible HTML Payload Silently Hijacked Every Email Summarizer Run
        "Indirect prompt injection has moved from academic exercise to field-deployed threat. Forcepoint X-Labs previously demonstrated how multi-agent email pipelines can be manipulated through PromptSpy and identified real IPI attacks in the wild. This post presents a measured laboratory proof of concept: we isolated a single email summarizer running an unguarded LLM pipeline, embedded a hidden prompt injection payload using common HTML concealment techniques, and ran both benign and injected emails through the system with pre-registered success criteria. The results confirm that indirect prompt injection can silently hijack summarizer output without signaling tampering to the reader."
        https://www.forcepoint.com/blog/x-labs/html-payload-hijacks-email-summarizer
        https://www.darkreading.com/cyber-risk/hidden-prompts-trick-ai-false-email-summaries
      • ZeroTokens: Phishing Platform Gives Operators Real-Time Control Of Attack Flow
        "ZeroTokens is a phishing platform built for financial institution impersonation at significant scale, combining reusable infrastructure with institution-specific verification sequences across dozens of financial brands. ZeroTokens operates less like a conventional phishing kit and more like a scam call center running through the target’s browser. A human operator watches each session unfold, sees information as the target enters it, and decides which prompt appears next. In parallel, the operator can use that information in a separate session with the genuine financial institution, coordinating the two interactions in near real time without proxying the bank."
        https://abnormal.ai/blog/zerotokens-real-time-phishing-platform
        https://www.infosecurity-magazine.com/news/zerotokens-phishing-real-time/
      • Extended Rapid Response: Zimperium Identifies RecruitTrap Recruit Scams Are Targeting Enterprise Credentials On Mobile
        "The recent research on The Growing Threat of Browser-in-the-Browser (BitB) Recruitment Scams highlights an escalating trend in social engineering: threat actors impersonate real HR personnel across multiple well-known companies to execute highly convincing, interview-themed phishing attacks. By scraping public profile data, attackers craft hyper-realistic scheduling flows designed to bypass traditional user skepticism. While desktop users encounter a simulated popup browser window (BitB), mobile devices present a unique vulnerability. On smaller screens, the attack automatically adapts, replacing the BitB frame with a full-screen counterfeit login page. Without traditional desktop browser chrome or visible URL bars, mobile victims have virtually no visual indicators to distinguish a fake login from a legitimate OAuth prompt."
        https://zimperium.com/blog/extended-rapid-response-zimperium-identifies-recruittrap-recruit-scams-are-targeting-enterprise-credentials-on-mobile
        https://www.infosecurity-magazine.com/news/fake-recruiter-scams-corporate/
      • Mirage2FA Surge Hits 4,500 US And EU Companies, Abusing Microsoft 365 Login Flows
        "Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based."
        https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html
      • SLEEPWALKER: A Passive Backdoor With Its Own Command Language
        "Losing access to VirusTotal Intelligence at the start of the year was surprisingly productive. Unable to hunt for interesting new malware, I stopped adding to my “TODO” pile and finally worked through my backlog from last year. That led to a detailed examination of BeheMOF as well as the discovery of this malware. Upon closer inspection, a sample that did not seem too noteworthy at first turned out to have a distinctive design once I looked under the hood: a passive backdoor that opens no obvious listening port and carries no payload inside itself. It waits in memory doing nothing at all until one specifically crafted network packet reaches the machine, which is why I am calling it SLEEPWALKER."
        https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/
        https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021

      Breaches/Hacks/Leaks

      • LACMA Data Breach Last Year Exposed Social Security And Medical Data
        "The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. The museum says that on July 11, 2025, it detected suspicious activity on its systems that had started four days earlier. A month later, the investigation confirmed that the network was compromised. At the time, the type of exposed data could not be determined, and the first results of the investigation became available in late February 2026."
        https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/
      • Hospital Operator Nutex Health Says Data Stolen In Cyberattack
        "Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. The organization has disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC), noting that the stolen data includes details that may be private or confidential. “Based on preliminary findings from the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including some information that may be private and/or confidential,” Nutex says."
        https://www.bleepingcomputer.com/news/security/hospital-operator-nutex-health-says-data-stolen-in-cyberattack/
      • Hackers Breached Over 270 Zimbra Servers In Ongoing Attacks
        "Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide. Synacor patched the security flaw (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of ZCS version 10.1.20 on July 20."
        https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/
        https://www.bankinfosecurity.com/zimbra-exploitation-spreads-as-thousands-stay-unpatched-a-32654
        https://www.helpnetsecurity.com/2026/08/25/zimbra-cve-2026-73570-compromised/
      • Employee Benefits Platform Paylogix Says Hackers Stole Financial And Health Data
        "Hackers stole troves of sensitive information on tens of thousands of people from Paylogix, a tech company that provides benefits management tools to employers and insurance firms. The company has notified several state regulators this month and published its own notice of a security incident explaining that it experienced a cyberattack in the fall that disrupted its systems. An investigation revealed that hackers stole files from the company’s network between November 13 and November 18. Paylogix did not identify the hackers, but the company was added to the leak site of the Akira ransomware gang in January."
        https://therecord.media/paylogix-cyberattack-akira-ransomware

      General News

      • AI Supply Chain Risk Is Showing Up In Developer Workflows First
        "In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research demos. He explains why segmentation buys more risk reduction per dollar than tooling, where self-hosting a model falls short, and which semiconductor isolation practices software teams should copy. He also names the security belief he has since abandoned."
        https://www.helpnetsecurity.com/2026/08/25/jaushin-lee-ai-zentera-systems-supply-chain-risk/
      • A Tale Of Two SOCs: Insights From Two Red Team Assessments
        "The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model. This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a
        https://www.cisa.gov/sites/default/files/2026-08/aa26-237a-tale-of-two-SOCs-insights-two-red-team-assessments-508c.pdf
        https://cyberscoop.com/cisa-red-team-report-government-water-cybersecurity/
      • 58 Arrests In Global Effort To Dismantle West African Organized Crime Groups
        "An eight-month operation targeting West African organized crime groups has led to 58 arrests and the identification of 263 suspects. Operation Jackal IV (November 2025 – June 2026) aimed to disrupt money laundering, identify high-value targets, seize assets, and support arrests and prosecution. The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups. These groups are responsible for a significant share of the world's cyber-enabled financial fraud, typically through romance scams, cryptocurrency and investment scams or business email compromise fraud, as well as other serious and violent crimes."
        https://www.interpol.int/News-and-Events/News/2026/58-arrests-in-global-effort-to-dismantle-West-African-organized-crime-groups
        https://www.bleepingcomputer.com/news/security/police-arrests-dozens-of-suspects-in-global-cybercrime-crackdown/
        https://therecord.media/58-arrested-international-cybercrime-crackdown-interpol
        https://cyberscoop.com/interpol-operation-jackal-iv-black-axe-arrests/
        https://www.helpnetsecurity.com/2026/08/25/interpol-jackal-iv-west-african-crime-groups-arrests/
      • Most Organizations Declare Victory Over a Breach Too Early
        "That is often the moment an organization wants to believe the worst is over. Services are restored. Customers can transact again. Executives can brief the board that operations have resumed. Communications teams can move from crisis language to recovery language. Operationally, that may be true. But from a security perspective, it's often premature. One of the most persistent weaknesses among incident response teams is their tendency to confuse service restoration with breach recovery. The organization rebuilds servers, restores applications, re-enables user access and resumes business processes. But the deeper questions remain unresolved."
        https://www.bankinfosecurity.com/blogs/most-organizations-declare-victory-over-breach-too-early-p-4179
      • The Safety Penalty: Reclaiming Operational Sovereignty In The Age Of AI
        "Cybersecurity has made a big bet on cloud-hosted AI. Building and running frontier-class models in-house isn’t realistic for most security teams — the compute, the talent, and the R&D costs are more than any single SOC can carry. So we’ve effectively outsourced the "brain" of our security operations to a handful of providers. That trade comes with a hidden cost: the safety penalty. The safety penalty is the friction that shows up when guardrails built to protect the general public get in the way of legitimate security work. If your model refuses to deobfuscate that malware or to explain a working exploit because its filters read the request as harmful, you’re paying the safety penalty."
        https://blog.talosintelligence.com/the-safety-penalty-reclaiming-operational-sovereignty-in-the-age-of-ai/
      • From ‘High/Medium/Low’ To Dollars: Making Cyber Risk Legible To Your CFO
        "For years, cybersecurity teams have communicated risk through labels such as “High,” “Medium,” and “Low.” Those ratings can help security teams prioritize vulnerabilities, but they often leave CFOs with a more important question unanswered: What does the risk actually mean for the business financially? That question has become harder to ignore as the threat landscape accelerates. Cyble’s 2025 threat predictions, published as the year unfolded, provide a useful illustration. More than 80% of the threats Cyble forecast—including AI-driven ransomware and complex supply-chain attacks—materialized as anticipated."
        https://cyble.com/blog/financial-exposure-cyber-risk-quantification/
      • Is Cyber Facing An Affordability Crisis?
        "A chief information security officer—if the company can even afford one— is woken by an urgent phone call in the middle of the night. There's been a breach. Threat actors stole highly sensitive customer data, and now they're demanding a ransom. If the company doesn't pay, they will leak data on the Dark Web. That's when the clock, and the financial fallout, starts ticking. Whether it's a ransomware attack, business email compromise, or a third-party supply chain attack, organizations have unfortunately become increasingly accustomed to suffering data breaches. But they are caught between rising threats they can't ignore and burgeoning defense costs they can't sustain."
        https://www.darkreading.com/cybersecurity-operations/is-cyber-facing-an-affordability-crisis-
      • Silent Patches Don’t Stop Attackers – They Blind Defenders
        "Every so often a vendor decides the smart move is to fix a vulnerability quietly. No advisory, no CVE, no explanation, just the vaguest handwave in a changelog. The logic sounds reasonable on its face: if you don’t explain what a patch does, you avoid handing attackers a roadmap to the root cause. Why publicize your bugs? Here’s why: patches aren’t secrets once they ship. A vendor can skip the CVE, skip the advisory, skip the outreach, but the binary still changes on disk, and anyone with a debugger and a disassembler can diff old and new and figure out what moved. That’s not a hypothetical skill, and lately, the barrier to entry into sophisticated exploit dev just got a lot lower thanks to our LLM friends."
        https://www.securityweek.com/silent-patches-dont-stop-attackers-they-blind-defenders/
      • Leak Sites: a Field Guide
        "A leak-site listing is a claim, not a confirmation. Ransomware groups use leak sites as part of their extortion strategy, so defenders should seek corroborating evidence before treating a listing as proof of a breach. Leak sites provide useful threat intelligence, but they require context. They can reveal active threat groups, targeted industries and emerging campaigns, but listings may include exaggerated, recycled or unverified claims. Focus on trends and exposure, not raw victim counts. The most valuable insights come from identifying which sectors, vendors and organizations are being targeted and determining whether they present risk to your environment or supply chain."
        https://blog.barracuda.com/2026/08/25/leak-sites-a-field-guide
      • The State Of AI-Enabled Malware August 2026: From Brand Abuse To Agentic Execution
        "To assess the impact of AI-enabled malware, we collected and analyzed over 400 malware samples that integrate AI in some capacity, from brand impersonation and large language model (LLM)-generated code to agentic execution loops. Our central finding was that the AI malware space is currently overwhelmingly composed of proof-of-concept code, security validation testing and researcher submissions that have never reached a production environment. Of the 405 samples in our dataset, only 12 appeared in our telemetry on Cortex XDR-protected endpoints, and a small subset was forwarded through Next-Generation Firewalls to WildFire for analysis. Palo Alto Networks products detected and blocked every sample that attempted to reach a customer environment."
        https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
      • New Bitsight Research Shows AI Abuse Is Moving Beyond The Jailbreak Prompt
        "Jailbreak prompts (i.e. prompts designed to remove or bypass the guardrails and rules that govern AI systems, like LLMs) prompts have been circulating for years. At first, a lot of it was pretty simple: copy a prompt, tell the model to ignore its rules, and see what happens. It was also largely noisy, unverified, and often didn’t work. But the noise was still telling us something. Threat actors were beginning to study AI systems the same way defenders were, and over time, the goal started to change. New Bitsight Threat Intelligence research from July 2025 through July 2026 found jailbreak activity across forums, GitHub repositories, Telegram channels, direct messages, and marketplace-style conversations. We also saw users moving past static prompts and experimenting with obfuscation, model routing, retry logic, multi-model testing, and repeatable jailbreak workflows."
        https://www.bitsight.com/blog/ai-jailbreak-prompts-evolving-cyber-threats

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 843341be-edfa-413d-bce3-de618d0c695a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีช่องโหว่ miniOrange บน WordPress เสี่ยงข้ามการยืนยันตัวตน

      พบการโจมตีช่องโหว่ miniOrange บน WordPress เสี่ยงข้ามกา.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9366397d-4f94-40ec-937b-a7391decc53e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • อาชญากรไซเบอร์ใช้กระแส GTA VI Leak หลอกแพร่กระจาย Malware ผ่านไฟล์เกมปลอม

      อาชญากรไซเบอร์ใช้กระแส GTA VI Leak หลอกแพร่กระจา.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand da506c39-d1fe-4eb1-8345-88f077ab083f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตือนภัยมัลแวร์ Weedhack แฝงตัวในโปรแกรมเสริมของเกม Minecraft เลียนแบบเว็บไซต์จริงเพื่อขโมยข้อมูล

      เตือนภัยมัลแวร์ Weedhack แฝงตัวในโปรแกรมเสริมข.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2208baf2-aaf9-4fdc-a698-3b32632bb65d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Keycloak ออกแพตช์ช่องโหว่ Critical เสี่ยงถูกเข้าควบคุมบัญชีผ่านการรีเซ็ตรหัสผ่าน

      Keycloak ออกแพตช์ช่องโหว่ Critical เสี่ยงถูกเข้าควบค.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7b120224-0ca2-406d-ad46-9e2022718f13-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • สโลวาเกียเตือนความเสี่ยง Cybersecurity ใน Speed Camera อาจกระทบข้อมูลรถและระบบเครือข่ายภาครัฐ

      สโลวาเกียเตือนความเสี่ยง Cybersecurity ใน Speed Camera อาจก.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5f179050-5c16-454f-ab14-6393cebc870b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Anthropic ขยายการเข้าถึง AI โมเดล Mythos 5 เสริมเกราะป้องกันไซเบอร์

      Anthropic ขยายการเข้าถึง AI โมเดล Mythos 5 เสริมเกราะป้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b8036fe3-6841-41f9-b290-08dc26814087-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 25 August 2026

      Financial Sector

      • Security Issues In The Korean & Global Financial Sector In July 2026
        "In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from 1.4 The previous month. In Stage 3, Infostealers (malware designed to steal information) were the most prevalent at 0.2, While Ransomware and CoinMiner each accounted for 0.1."
        https://asec.ahnlab.com/en/95109/
      • Venezuelan Gets Record Federal Prison Term For ATM Jackpotting
        "A Venezuelan national has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions of dollars in losses, the US Justice Department announced on Friday. According to the DOJ, 27-year-old Juan Manuel Gouveia-Aguilera has been sentenced to 96 months in prison, 5 years of supervised release, and ordered to pay restitution after pleading guilty to bank fraud, bank burglary, and cyber-enabled fraud charges. “The Court found Gouveia-Aguilera to be responsible for more than $3.5 million in losses and this sentence is believed to be the longest federal sentence imposed for an individual’s role in ATM jackpotting,” the DOJ said."
        https://www.securityweek.com/venezuelan-gets-record-federal-prison-term-for-atm-jackpotting/

      Vulnerabilities

      • One Slug, Seven Editions: The MiniOrange SAML SSO Bug That Let Anyone Log In As Your WordPress Admin
        "Most vulnerability write-ups are about the bug. This is primarily about everything around the bug, where the actual risk ended up living. The DigitalOcean security team identified a critical gap the hard way, based on their defense-in-depth controls. The version-level analysis that follows, which no public vulnerability database had, came out of DigitalOcean’s work. Two critical authentication bypasses (CVSS 9.8) were publicly disclosed in July 2026 for the miniOrange SAML 2.0 Single Sign On plugin (opens in new tab)↗. Both allow an unauthenticated attacker to forge a SAML assertion and land in /wp-admin as any existing user, including administrators."
        https://patchstack.com/articles/one-slug-seven-editions-the-miniorange-saml-sso-bug-that-let-anyone-log-in-as-your-wordpress-admin/
        https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/
      • Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
        "Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as the CVE Numbering Authority (CNA) for the flaw. It has been classified as a weak password recovery mechanism for a forgotten password (CWE-640). Users of upstream Keycloak are advised to update to version 26.7.2, released August 19, 2026, while customers running Red Hat build of Keycloak (RHBK) should apply the updates shipped for 26.4.15 and 26.6.6."
        https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
      • 91 Vulnerabilities Patched In Spring Application Framework
        "The developers of Broadcom’s Spring application development framework last week announced the release of updates that patch 91 vulnerabilities. Spring is an open source application framework for the Java platform that simplifies the creation of enterprise applications through features such as dependency injection, aspect-oriented programming, and modular support for web, data, and messaging architectures. After years under VMware’s stewardship, it transitioned to Broadcom following its acquisition of VMware."
        https://www.securityweek.com/91-vulnerabilities-patched-in-spring-application-framework/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog
      • Calix GS7 XGS GS5239XG Residential Router Contains Missing Authentication Vulnerability
        "The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface. Calix GS7 XGS GS5239XG is a residential gateway that provides routing, NAT, and firewall functionality for home networks. The device includes the Universal Plug and Play (UPnP) service implemented via MiniUPnPd 2.3.7, a lightweight software program that provides features such as automatic port forwarding for applications and devices on the LAN. By default, the UPnP service is exposed on the device’s WAN interface and does not require authentication."
        https://kb.cert.org/vuls/id/756733
        https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/
      • Russian Backdoor Found In Slovak Traffic Cameras
        "Efforts to modernize state infrastructure and update traffic surveillance have been stalled by critical security issues the Slovakian government reported in newly acquired high-speed traffic cameras. The National Security Authority - Slovakia's watchdog cybersecurity agency - discovered backdoors embedded in a module in 279 NERO R-ONE high-speed cameras. The now disabled cameras - acquired through a 30 million euro European Union-backed modernization fund - contained a collection of Russian-linked phone numbers that enable backdoor access to the country's traffic systems."
        https://www.bankinfosecurity.com/russian-backdoor-found-in-slovak-traffic-cameras-a-32645
        https://securityaffairs.com/197764/hacking/slovakia-warns-of-cyber-risks-in-road-speed-cameras.html
      • Cudy WR3000 Router Flaws Can Be Chained To Gain Root Access
        "Independent security researchers Hunt & Benito have released public exploit tools that reproduce a two-vulnerability chain affecting Cudy WR3000 routers. The code can extract authentication data from the router firmware, forge a valid token, and, when the required network access exists, execute operating-system commands as root. The toolkit was published on August 20, 2026, one day after GitHub published advisories for the vulnerabilities. Its release turns the technical findings into a repeatable exploitation process, although there is no evidence that either flaw is being exploited in real attacks."
        https://hackread.com/cudy-wr3000-router-flaws-chained-root-access/

      Malware

      • A Social Engineering Attempt Against ReliaQuest: What We Found
        "On August 22, 2026, ReliaQuest was the target of a social engineering attack. While unsuccessful beyond temporarily exposing one identity, the attempt was an important reminder of the persistent tactics of threat actor groups and what all organizations can do to guard against them. We are sharing the full details of this attempt for transparency and so others can learn from this playbook. The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network. The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard."
        https://reliaquest.com/blog/threat-spotlight-social-engineering-attempt-against-reliaquest-what-we-found/
        https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/
        https://www.securityweek.com/reliaquest-confirms-shinyhunters-hack-but-says-impact-was-limited/
      • AliExpress Webpage Keeping Multipoint Bluetooth Headphones Active With WebAudio Fingerprinting
        "Recently I ran into a strange problem with my Bluetooth headphones. They support multipoint Bluetooth audio, so they can be connected to my PC and phone at the same time. Normally the PC takes priority playing audio, with my phone being able to play audio when nothing is playing on the PC. Usually I listen to music on my phone but with notifications or Youtube playing through the PC, this works reliably until I open an AliExpress page in Firefox or Chrome (other browsers untested). Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately. Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page."
        https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html
        https://www.bankinfosecurity.com/alibabas-aliexpress-uses-hidden-audio-to-fingerprint-devices-a-32646
        https://www.malwarebytes.com/blog/privacy/2026/08/aliexpress-caught-using-silent-audio-to-fingerprint-visitors-browsers
      • WordlistLoader Delivering Amatera Via ClearFake Campaigns
        "Over the past few months, Amatera Stealer (also often referred to as ACR Stealer) has been actively developed and has gradually become one of the most prevalent infostealer in our user base. Most recently, we've been observing Amatera being distributed via ClearFake campaigns leveraging FakeCaptchas. Although FakeCaptcha, as a technique, is well-known and has been documented countless times, it has proven to be one of the most effective social engineering techniques for luring victims into infecting their own machines, which is why we still keep seeing it so often in malware campaigns, and why we proactively defend against these types of attacks with our Clipboard protection."
        https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
        https://www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text
        https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html
      • The "Chameleon" Threat: Unmasking And Mitigating Cloaked SEO Poisoning In Financial Services
        "In Q2 2026, Fortra Intelligence and Research Experts (FIRE) observed a more than 40% increase of threat actors weaponizing trust through a new tactic dubbed by researchers as “Chameleon SEO Poisoning.” The tactic uses cloaked search engine results to deploy phishing payloads such as credential theft and session hijacking. This allows them to remain invisible to standard security scanners and remain active longer. To successfully detect and mitigate these campaigns, security teams should move beyond relying solely on static automated sweeps and integrate context-aware, emulated scanning that mirrors a victim’s search journey."
        https://www.fortra.com/blog/the-chameleon-threat
        https://www.helpnetsecurity.com/2026/08/24/chameleon-seo-poisoning-fake-banking-websites-phishing/
      • Cato CTRL Insights: When Trust Becomes The Payload In a Fake Codex ClickFix Campaign
        "Attackers are using a fake Codex download experience to trick macOS users into pasting a malicious command into Terminal. This technique, known as ClickFix, relies on social engineering rather than a conventional malware download: the victim is persuaded to perform the execution step themselves. We analyzed sponsored search results leading to convincing Google Sites pages, a no-code website-building and hosting service provided by Google. An attacker-controlled embedded page then presented the fake installer and the Terminal instruction."
        https://www.catonetworks.com/blog/cato-ctrl-when-trust-becomes-payload-in-fake-codex-clickfix-campaign/
        https://www.infosecurity-magazine.com/news/fake-codex-download-google-sites/
      • DOUBLOON DREDGER Token Harvesting: Notion Abuse, EvilTokens, And a Side Of Tycoon2FA
        "In July 2026, a Sublime customer reached out about having observed Notion abuse for the purpose of delivering phishing attacks. In parallel, Sublime Threat Intelligence & Research (STIR) had identified similar phishing activity directed at another customer in a similar vertical. In these attacks, the threat actor abuses Notion by creating a fake account and then invites targets to view a PDF that contains a malicious link. The payload link then takes the target to an EvilTokens device code harvesting page."
        https://sublime.security/blog/doubloon-dredger-token-harvesting-notion-abuse-eviltokens-and-a-side-of-tycoon2fa/
        https://www.infosecurity-magazine.com/news/doubloon-dredger-notion/
      • Fake GTA 6 Extended Look And Demo Sites Deliver An Infostealer
        "GTA 6 footage really has leaked online, and Rockstar has an official Extended Look coming to Netflix on August 27. But cybercriminals are exploiting the hype with fake Rockstar sites that lead visitors to password-stealing malware. We identified a network of sites appearing in searches for a GTA 6 demo and impersonating Rockstar Games. One Google result advertises an “Official Download,” but visitors who follow the sites’ “Play Now” links can instead end up downloading gta6_installer.exe."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer
        https://www.tomshardware.com/video-games/fake-gta-vi-iso-circulates-on-the-internet-a-few-days-after-leak-internet-sleuths-claim-113gb-download-is-padded-malware-testers-claim-file-is-99-99-percent-empty-zeroes-with-50kb-virus-embedded
        https://securityaffairs.com/197772/malware/cybercriminals-turn-gta-vi-leaks-into-malware-bait.html
      • Fake Microsoft Security Scans Trick Victims Into Uninstalling Their Antivirus
        "A wave of websites is offering to check whether your antivirus is working. They call themselves SysScan, carry Microsoft branding, and all reach the same conclusion: Your computer has serious problems, and the cause is the antivirus software you installed. Windows, they claim, no longer supports third-party antivirus. Uninstall it immediately. That is false, and it is the first step in a refund scam designed to get victims onto the phone, remove their security software, and ultimately hand over personal, banking, and remote-access information."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus
      • Tracking PavinLoader Across ClickFix And Fake Download Campaigns
        "In our previous analysis of the malicious RenPy campaigns, we identified a multi-stage loader deployed as part of the infection chain. Further threat hunting has since shown that the same loader, which we track as PavinLoader, is being used across several different campaigns, including ClickFix attacks and fake software downloads. Despite differences in how these campaigns reach victims, we found several common elements."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns
      • Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats Via VHD-Delivered Go Backdoor
        "Seqrite APT Team has been tracking threat activity across the globe, with a focus on campaigns targeting different industries and regions. During our recent research, we found a campaign targeting Myanmar that uses a Burmese-language graduation ceremony invitation from Myanmar’s Information Technology and Cyber Security Department as lure. The threat actor delivers the malware through a Virtual Hard Disk (VHD) file. While analyzing the VHD, we discovered several interesting artifacts. we also recovered files from the Recycle Bin that appear to have been unintentionally left behind by the threat actor. These overlooked files provided valuable context that helped us better understand the campaign’s attribution."
        https://www.seqrite.com/blog/operation-quicsilver-china-nexus-actor-targets-myanmar-diplomats-via-vhd-delivered-go-backdoor/
        https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.html
      • Active Exploitation Of a Software Development Platform Within Australia
        "The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia. TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server to automate the processes of building, testing, and deploying software. CVE 2026-63077 may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands."
        https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/active-exploitation-of-a-software-development-platform-within-australia
      • Connecting The Dots: Securing The Overlooked Corners Of The Software Development Lifecycle (SDLC) Supply Chain
        "While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in finished software, attackers are targeting the everyday tools and code developers rely on. Unit 42 research shows this happening at every step of the building process. We've observed attackers spending years pretending to be helpful contributors just to hide backdoors in core software, as seen in the XZ Utils vulnerability (CVE-2024-3094). We've seen attackers hijack accounts to drop malware into popular libraries, like in the Axios supply chain attack. And we've seen them misuse setup scripts to automatically steal credentials using the Shai-Hulud npm worm."
        https://unit42.paloaltonetworks.com/sdlc-supply-chain/

      General News

      • July 2026 Threat Trend Report On Ransomware
        "The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred to as ransomware PR sites or PR pages) operated by ransomware groups."
        https://asec.ahnlab.com/en/95112/
      • Treasury Launches Unprecedented Campaign Against Iranian Regime On Economic D-Day
        "Today, at President Trump’s direction, the U.S. Department of the Treasury has begun Operation Economic Outcast: an unprecedented, whole-of-government, economic campaign against the Islamic Republic of Iran and its enablers. “In the Second World War, D-Day marked the historic beginning of a campaign with our allies to target and drive the enemy from its positions, including those in third countries. Today, in that same spirit, we are launching an economic onslaught against Iran’s financial connections around the globe."
        https://home.treasury.gov/news/press-releases/sb0613/
        https://therecord.media/iran-cyberattacks-us-uk
        https://cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/
      • The Vulnerability Gap: Why Discovery Is Outrunning Repair
        "For decades, finding a serious vulnerability in widely used open source software was specialized work. It took a skilled researcher weeks, sometimes months, to trace a flaw and responsibly bring it to a maintainer. That timeline has effectively collapsed. Advanced AI models can now produce vulnerability reports in hours, demolishing what a seasoned professional would have taken weeks to develop. That's not hypothetical: it's what the open source security community has watched happen since the fall of last year, as tools built on frontier models and strong open-weight models alike started turning out findings that are, frankly, good."
        https://www.darkreading.com/cybersecurity-operations/vulnerability-gap-why-discovery-is-outrunning-repair
      • CISA Releases Foundational, Flexible Guidance To Help Federal Agencies Implement Effective Logging, Visibility And Operational Standards
        "Today, the Cybersecurity and Infrastructure Security Agency (CISA) published the Logging Reference Architecture, an outcome-driven guide for federal civilian executive branch (FCEB) agencies to establish logging, visibility and operational standards in an Agency Logging Plan, as required in Office of Management and Budget (OMB) Memorandum M-26-14. Developed in collaboration with OMB and the Chief Information Security Officers (CISO) Council, this guidance implements a practical, risk-based, prioritized logging approach that improves agency network monitoring. In alignment with the objectives of M-26-14, CISA’s Logging Reference Architecture guidance directly helps agencies achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response, and forensics. Agencies will be able to utilize this guidance to update enterprise logging strategies, which will inform an Agency Logging Plan that agencies are required to submit to OMB and CISA by November 18, 2026. The M-26-14 Agency Logging Plan Template, provided by CISA, offers a structured format to streamline planning."
        https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging
        https://www.cisa.gov/resources-tools/resources/logging-reference-architecture
        https://www.cisa.gov/sites/default/files/2026-08/logging-reference-architecture.pdf
        https://www.helpnetsecurity.com/2026/08/24/cybersecurity-logging-guidelines-strategy/
      • New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims
        "As organizations race to future-proof their systems against quantum-enabled attacks, questions remain around how to verify whether hardware is quantum-safe. A new industry benchmark aims to answer that question. The Trusted Computing Group (TCG) released new guidance on August 24 that helps prove that trusted platform modules (TPMs) genuinely meet essential PQC requirements. TCG is a nonprofit organization tasked with promoting vendor-neutral standards for hardware-based security products like TPMs."
        https://www.infosecurity-magazine.com/news/guidance-verify-quantum-safe/
        https://trustedcomputinggroup.org/is-your-tpm-truly-pqc-ready/
      • Multi-Cloud Architecture Challenges: Security And Compliance Implications
        "NIST Internal Report (IR) 8613 ipd (initial public draft), Multi-Cloud Architecture Challenges, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis by the NIST Multi-Cloud Security Public Working Group (MCSPWG) addresses security and Authorization to Operate (ATO) challenges and highlights areas where additional community research could meaningfully reduce risk. The MCSPWG identified 23 consolidated challenge areas that represent novel friction points and architectural misalignments that emerge when orchestrating control across autonomous cloud silos."
        https://csrc.nist.gov/pubs/ir/8613/ipd
        https://www.infosecurity-magazine.com/news/nist-risks-multi-cloud/
      • Hired For One Job, Judged On Another: The CISO’s Real Problem
        "Industry surveys have long put CISO tenure below that of other C-suite roles, and part of the reason is a double standard. During recruitment, the focus is technical depth, security experience, and leadership. But when budget season arrives and the board weighs a leader’s performance, the lens is cost, growth, customer trust, and brand protection. Many CISOs feel this acutely. They came up through security, or through risk and compliance, and that is where they are fluent. Their board is not. It wakes up thinking about cost, growth, and customer commitments, and a security leader who cannot connect their work to that language will be seen as important, but rarely as strategic."
        https://www.securityweek.com/hired-for-one-job-judged-on-another-the-cisos-real-problem/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 34425d3f-e25e-4d0e-9986-33f5ddb7307d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 24 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f7fe83c0-4872-448b-ba8a-e1390b4447fd-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 24 August 2026

      Financial Sector

      • When Fraud Needs a Bank: Inside An Ecosystem Built To Manufacture Trust
        "An exact search for the phrase “one of the largest digital banking providers” in the source code of publicly available websites flagged approximately 2,200 domains. We investigated each one. Of the sites that still carried the phrase, 97% retained artifacts from Cuex, a commercially available template designed for currency exchange and money transfer websites. It cost $25 at the time of our research. That inexpensive visual layer had been adapted into applications with login and registration forms, investment and transfer language, account dashboards, and other bank-like functions. We call this layered approach legitimacy stacking. Those capabilities work alongside corporate details, compliance claims, and support channels to make an invented institution appear credible. The resulting financial front can provide a convincing pretext for investment, loan, romance, recovery, and advance-fee fraud. One sentence exposed the collection of domains. Deeper investigation and campaign mapping surfaced code, assets, form destinations, identifiers, and public records that ultimately showed how its pieces were connected."
        https://alluresecurity.com/blog/signal-noise-when-fraud-needs-a-bank/
        https://www.helpnetsecurity.com/2026/08/21/phantom-bank-websites-fraud-research/

      Industrial Sector

      • How An Emerging Industrial Protocol Family Could Put OT At Risk
        "In operational technology (OT) networking, the reliability and availability of industrial processes trumps everything, even cybersecurity. But what happens when an OT networking protocol designed to ensure speedy availability of safety-critical communications also embeds a security weakness into the architecture? Without a full slate of cyber controls folded in, that reliability mechanism could itself become a vehicle for the kinds of industrial failures it's supposed to help prevent."
        https://www.darkreading.com/ics-ot-security/how-emerging-industrial-protocol-family-put-ot-at-risk

      Vulnerabilities

      • Microsoft Warns Of Max Severity Entra ID Flaw Exploited In Attacks
        "Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. Formerly known as Azure Active Directory (or Azure AD), it is a cloud-based IAM platform that provides Microsoft 365, Azure, or Dynamics CRM Online customers with authentication, policy enforcement, and protection across apps and resources. Tracked as CVE-2026-69836, this critical security flaw was discovered by Microsoft principal security engineer Robert Fitzpatrick, and it allowed threat actors with no privileges to gain code execution in low-complexity attacks."
        https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/
        https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
        https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html
        https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/
        https://www.helpnetsecurity.com/2026/08/21/microsoft-entra-id-vulnerability-cve-2026-69836/
      • Cisco Patches Nine Crosswork And Secure Workload Flaws, Five Scoring CVSS 10.0
        "Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below -"
        https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html
        https://securityaffairs.com/197640/security/six-maximum-severity-flaws-found-in-cisco-products.html
        https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838
      • GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days Of Disclosure
        "A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring credentials, user interaction, or obscure configuration."
        https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
        https://securityaffairs.com/197622/uncategorized/gitlab-warns-of-active-exploitation-of-critical-graphql-flaw.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog
        https://securityaffairs.com/197693/security/u-s-cisa-adds-zimbra-collaboration-suite-zcs-flaw-to-its-known-exploited-vulnerabilities-catalog.html
      • Microsoft Defender's Own Driver Can Be Weaponized To Delete Security Software At Boot
        "Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a required Windows component, which means it cannot be added to Microsoft's Vulnerable Driver Blocklist or blocked via Windows Defender Application Control (WDAC) without disrupting Defender itself."
        https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html
        https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/
      • Reverse-Engineering Find My People To Stalk My Ex a Friend, Cause I Can
        "As it can often be, I was bored. I wanted to look into a complex system, and had no idea which. Me and a friend have been sharing our locations to each other’s through Apple’s “Find My”. I asked if he was okay with me piping it into some dumb automations. He said yes, so the plan was to draw a few geofences around places he goes and make Discord announce whenever he arrived or left."
        https://zerotistic.blog/posts/find-my-people-linux/
        https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496

      Malware

      • SynkLoader: When You Throw In Everything But The Kitchen Sink
        "On August 18, we encountered a novel malicious loader while investigating an incident on a client network where the EDR alerted on a scheduled task. There appeared to be no public references to the loader or any of its components; every part of it appeared to be relatively new, with compile dates and file timestamps indicating it was first compiled and distributed around July 28, 2026. To see what the loader would do and what kind of components it might run, we reverse engineered it and created a modified version which logged the attacker’s commands instead of executing them. We also provided the loader with fake system information, making it look like the threat actors had infected a large corporate network."
        https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/
        https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/
      • FTP Banners: The New Dead Drop Resolver Delivering Novel RATs
        "Security products have become increasingly effective at detecting suspicious commands used for malware delivery. Consequently, threat actors are adopting more creative methods to bypass these defenses, such as utilizing Dead Drop Resolvers (DDRs): alternative locations, including legitimate web services or protocols, used to acquire malicious strings, Command and Control (C2) configurations, or commands. During an investigation, the SOCRadar Threat Research Unit (STRU) identified the active abuse of FTP banners as DDRs to distribute malicious commands, a technique observed in the wild since early July 2026. Further infrastructure analysis led to the discovery of two previously undocumented Remote Access Trojans (RATs), which we have named E4del and PINHOLE."
        https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/
        https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/
      • Fake AI, Real Malware: Attackers Impersonating AI Brands
        "Sophos X-Ops reviewed a year of Managed Detection and Response (MDR) cases tagged as ‘AI activity.’ Of the 34 cases that held up, nearly all were attackers creating fake versions of legitimate AI sites and software to infect users with malware. Attackers are exploiting the surge in demand for AI software by faking the software itself: names users trust, like Claude, ChatGPT, and Copilot, become delivery vehicles for malware. For defenders that is good news – or at least, not all bad – because malware is a problem that existing controls are designed to address."
        https://www.sophos.com/en-gb/blog/fake-ai-real-malware-attackers-impersonating-ai-brands
        https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/
      • Anatomy Of An Agent Tesla BEC Attack: From Inbox To In-Memory Infostealer
        "Phishing is a form of social engineering that has evolved beyond simple lures into complex, multi-stage attacks exploiting trusted software, cloud identities and business platforms to bypass traditional security. Attackers leverage these campaigns to deliver trojans capable of stealing credentials and also establishing remote code execution, which might serve as a gateway for lateral movement. This evolution enables them to maintain persistent access, making it harder for conventional email defenses to detect and mitigate these high-impact threats."
        https://blog.knowbe4.com/anatomy-agent-tesla-bec-attack-in-memory-infostealer
        https://www.infosecurity-magazine.com/news/agent-tesla-malware-evasion/
      • The Invisible Passenger In Your Car
        "While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might be reaching users’ devices without their knowledge. Further investigation confirmed that hypothesis and allowed us to reconstruct the entire infection chain."
        https://securelist.com/android-head-unit-malware/121106/
        https://thehackernews.com/2026/08/android-car-malware-spreads-through.html
        https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/
        https://securityaffairs.com/197700/hacking/malware-hijacks-android-car-head-units.html
      • Prompting The Payload: How An Npm Supply Chain Attack Delivers The RedC2 AI-Powered Linux Implant
        "Analysis revealed that a cluster of trojanized npm packages (posing as working calendar and streak utilities) each bundles a malicious Linux ELF payload alongside genuine date-math code. When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process. No install hook function call is needed; a single import anywhere in the dependency graph, even a transitive one, is enough to execute the payload. RedC2 4.0 introduced the bundled payload RedShell, a native Linux implant sold on Hack Forums as a cross-platform C&C framework with Windows, macOS, and Linux beacons. It also ships Red Agent, an LLM-backed layer exposed via /ra that turns natural-language intent, such as dumping credentials or locating files, into an ordered chain of beacon commands."
        https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/redc2-ai-powered-linux-implant
        https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html
      • iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets
        "When an account compromise is limited to a captured session, revoking that session and resetting the password normally cuts off the attacker’s access. iAuthFlow v2 can use that temporary foothold to establish a separate way back into the account. Once the target completes a phishable Google login, the toolkit uses the authenticated session to enroll a passkey controlled by the operator. In the seller’s recorded demonstration, the account owner later changes their password, invalidating the active session—but the operator authenticates with the newly enrolled passkey and returns to the mailbox."
        https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys
        https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/
      • Windows Infostealer Hits Npm And Ruby
        "Today, we came across independent research from OpenHack documenting a 37-package typosquatting campaign on npm, targeting chalk, commander, lodash, typescript, react, and axios. It described a 22 MB Rust loader carrying an embedded Go infostealer that decrypts entirely in memory with no second-stage download. That immediately caught our attention, because earlier this week we documented the RubyGems typosquatting campaign StubMaker, which has the same shape. That includes the specific file size."
        https://opensourcemalware.com/blog/windows-infostealer-stubmaker-npm-ruby

      Breaches/Hacks/Leaks

      • Iranian Hackers Shut Down UK Power Plant
        "Iran shut down a British power plant for four days in an unprecedented cyber attack, The Telegraph can disclose. It is thought to be the first time that hackers affiliated to the Iranian regime have succeeded in closing down such a facility in the UK, and is believed to be the most successful cyber attack of its kind. The Telegraph understands that the incident took place at the same time as a series of attacks on US water infrastructure last month, which affected 12 states and caused concern in the White House."
        https://www.telegraph.co.uk/news/2026/08/22/iranian-hackers-shut-down-uk-power-plant/
        https://www.bbc.com/news/articles/ce9793g34yvo
        https://securityaffairs.com/197734/cyber-warfare-2/uk-power-plant-disabled-for-four-days-by-iran-linked-hackers-concurrent-with-us-water-attacks.html
      • 768 Leaked Corporate AWS Keys Held Full Admin Rights
        "We re-verified 10,616 leaked AWS keys on August 10, 2026. They surfaced publicly between August 2022 and August 2026. 88% still authenticate. 768 of the live ones belong to a company and carry full control of its AWS account: 526 root keys plus 242 IAM users holding AdministratorAccess. The median live leaked key is five years old and has never been rotated."
        https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights
        https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/
      • SickKids Data Breach Exposes Employee And Job Applicant Info
        "The Hospital for Sick Children (SickKids) has disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a "cybersecurity incident." The hospital says the breach stemmed from a flaw in third-party software. Clinical systems and patient records were untouched, according to the Toronto pediatric hospital, but its public-facing Careers website was temporarily pulled offline."
        https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/
        https://therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data
      • ShinyHunters Leaks 7.1 Million Baxter International Records
        "Extortion gang ShinyHunters has struck the healthcare sector again. The notorious cybercriminal gang claims on its darkweb site of leaking 7.1 million Salesforce records stolen from medical device maker Baxter International, including personally identifiable information. "The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care," ShinyHunters wrote on a post on Wednesday that provided a button to download Baxter International's alleged stolen data."
        https://www.bankinfosecurity.com/shinyhunters-leaks-71-million-baxter-international-records-a-32630
      • U.S. Bank Says Breach Claims Related To Fourth-Party Incident
        "U.S. Bancorp said recent claims of data theft by a ransomware gang are related to a breach involving a contractor for a third-party, and do not impact its own systems or network. A spokesperson told Recorded Future News that U.S. Bancorp has investigated the claims and traced it back to “a potential cyber incident…related to a fourth party event that occurred outside” of their environment. “At this time, there is no evidence that our systems, networks or data repositories were compromised,” the spokesperson said. “We have provided relevant information to law enforcement and continue to support their investigation.”"
        https://therecord.media/us-bank-says-breach-claims-related-to-fourth-party-incident
        https://www.theregister.com/security/2026/08/20/us-bank-investigates-lockbits-claims-as-ransomware-crims-set-pay-or-leak-deadline/5290560
      • Russian Network Monitoring Firm Confirms Cyberattack Claimed By Pro-Ukraine Hackers
        "Russian software developer Microolap confirmed that hackers had compromised some of its systems but denied claims that they gained access to its network monitoring platform or stole data belonging to major Russian companies. Microolap, which develops software for intercepting and analyzing network traffic, said Thursday that it had detected an attempted breach of several non-critical systems but found no evidence that hackers accessed its core infrastructure, customer data or other sensitive information. "We urge people not to treat the attackers' claims as fact," Microolap CEO Andrey Smirnov said. "Our cybersecurity systems worked as intended: We detected the incident and kept critical data secure.""
        https://therecord.media/russian-network-monitoring-firm-confirms-cyberattack-claimed-by-pro-ukraine-group
      • Australian Hotel Chain Leaks Guests’ PII After Breach At Third-Party Database Operator
        "Australian aparthotel chain Quest has revealed it leaked customer data. A Reg reader kindly shared an email from the chain with the subject line “Important Security Update Regarding Your Quest Data.” That missive opens with unwelcome news that “I am writing to inform you of a recent data security incident involving some of your personal information.” “On Monday, 17 August 2026, we identified unauthorised access to a database system and immediately took steps to contain the incident,” the email continues. “The incident arose from a vulnerability through our third-party service provider.”"
        https://www.theregister.com/cyber-crime/2026/08/19/australian-hotel-chain-leaks-guests-pii-after-breach-at-third-party-database-operator/5289341
      • Apollo Discloses Data Breach From Ongoing Wave Of Attacks Hitting Financial Sector
        "Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday. Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notification filed in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment."
        https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/

      General News

      • July 2026 Infostealer Trend Report
        "This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs from AhnLab products."
        https://asec.ahnlab.com/en/95066/
      • Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates
        "Ransomware rarely appears out of nowhere. Before encryption, extortion, or data theft begins, attackers often spend time establishing access, stealing credentials, moving laterally, and identifying valuable systems. These activities occur during the ransomware pre-execution phase, when malicious activity may be difficult to distinguish from legitimate administration. For security teams, understanding ransomware attack vectors, ransomware initial access methods, and how ransomware evades detection is critical. Endpoint security blind spots can give attackers the time they need to prepare an attack without triggering an obvious alarm."
        https://cyble.com/blog/ransomware-attack-vectors-endpoint-blind-spots/
      • OpenAI Adds Controls That Should've Been There Already
        "OpenAI has committed to a number of security and guardrail improvements in the wake of an incident last month where cutting edge models inadvertently breached AI application store Hugging Face during a cyber capability benchmark exercise. Yet many of the newly announced controls appear less like groundbreaking safeguards and more like measures that should already have been in place for testing models with advanced cyber capabilities."
        https://www.darkreading.com/application-security/openai-adds-controls-already
      • Nearly Half Of Enterprises Have No One Leading PQC Migration
        "Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Organizations need to know where certificates, cryptographic keys and algorithms are used before they can plan a PQC migration. About 75% of respondents said they maintain a continuously updated inventory of these assets. However, responses about ownership and testing indicate that visibility does not always translate into migration readiness."
        https://www.helpnetsecurity.com/2026/08/21/axiad-pqc-migration-readiness-gaps-report/
      • Visualizing Infrastructure Security At Software Project Inception
        "The earliest stage of a software project carries engineering risks that are easy to overlook. The software does not yet exist, and the team is busy standing up infrastructure: provisioning servers, writing automation scripts, configuring access controls, and establishing the scaffolding that everything else will run on. The code that does this work—Terraform templates, Ansible playbooks, shell scripts, Dockerfiles—is software too, and it has vulnerabilities. The potential issue at this stage is specific: Scripts that create infrastructure can be exploited to open back doors. A misconfigured Identity and Access Management (IAM) role, an exposed port left open in a provisioning script, or an unpatched base image can quietly become an entry point that persists through every phase of the lifecycle that follows."
        https://www.sei.cmu.edu/blog/visualizing-infrastructure-security-at-software-project-inception/
      • Named Pipes Under Attack: Securing Windows Interprocess Communication
        "Named pipes are a common choice for communication between applications running on the same Windows computer. They are fast, supported directly by the operating system, and work well for communication between Windows services, desktop applications, tray processes, command-line utilities, and background agents. A typical design may include a privileged Windows service acting as the named-pipe server while a user-facing application connects as the client. Because both processes run on the same computer, developers often treat this communication as internal and therefore trusted."
        https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/
      • If You're Not Using AI To Attack Your Own Systems, Your Adversaries Will
        "AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions. As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies."
        https://www.theregister.com/security/2026/08/22/if-youre-not-using-ai-to-attack-your-own-systems-your-adversaries-will/5291346
      • Hardware Makers Implement Post-Quantum Cryptography As Security Threats Near
        "Chip makers are baking post-quantum cryptography acceleration into hardware as the threat of quantum systems breaking current encryption rises. The technology is still years away from the general market, but defenders are concerned about harvest-now-decrypt-later attacks that could build up stores of data until quantum computing becomes more widely available to exploit it. Security professionals and regulators encourage organizations to begin future-proofing now, and some key players are acting."
        https://www.darkreading.com/cyber-risk/hardware-makers-implement-post-quantum-cryptography

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 703712c6-89aa-435d-b220-b764d341d38a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • มัลแวร์ ToxicPanda 2.0 ใช้สิทธิ์ VPN บล็อก Google Play บนอุปกรณ์ Android

      มัลแวร์ ToxicPanda 2.0 ใช้สิทธิ์ VPN บล็อก Google Play บนอุปกร.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7b386658-ea6a-41c7-8e7d-e09fa82c5e9b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • มัลแวร์ยึด Android Car Head Unit เสี่ยงควบคุมระบบและขโมยข้อมูลผู้ใช้

      มัลแวร์ยึด Android Car Head Unit เสี่ยงควบคุมระบบและขโม.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 38fc4030-d007-413e-90be-3280fa2b0ce3-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้ผลิตฮาร์ดแวร์เร่งอัปเกรดชิปประมวลผลรองรับการเข้ารหัสยุค Post-Quantum เพื่อรับมือภัยคุกคามทางไซเบอร์ในอนาคต

      ผู้ผลิตฮาร์ดแวร์เร่งอัปเกรดชิปประมวลผลร.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2f3fe680-5783-4076-b61c-4298d4aaae6c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 21 August 2026

      Financial Sector

      • Zombie Card Attack Can Revive Expired Visa Cards For Contactless Payments
        "Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card's cryptography. The attack, which the researchers named "Zombie Card," requires physical possession of the expired card or sustained NFC proximity to it, plus a man-in-the-middle (MitM) relay positioned between the card and the terminal. It also requires that the account remain open under the same primary account number (PAN), which is standard practice when an issuer sends a replacement card, and that the issuing bank not independently re-check the expiry during authorization."
        https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html
        https://www.usenix.org/system/files/usenixsecurity26-anwar.pdf
        https://www.helpnetsecurity.com/2026/08/20/zombie-credit-card-attack-expired/

      Industrial Sector

      • A Brief Overview Of The Main Incidents In Industrial Cybersecurity. Q2 2026
        "In Q2 2026, 163 incidents were publicly confirmed by victims. All of these incidents are included in the table at the end of the overview, with select incidents described in detail. In our review of publications by researchers investigating threats to industrial organizations, we noted a significant increase in stories describing attacks on control systems intended to cause physical damage. Unsurprisingly, the number of such incidents confirmed by the attacked parties has also increased. The organizations that suffered most were obviously the ones not paying sufficient attention to the security of their automation systems for a number of reasons, primarily economic ones."
        https://ics-cert.kaspersky.com/publications/reports/2026/08/20/a-brief-overview-of-the-main-incidents-in-industrial-cybersecurity-q2-2026/
      • Johnson Controls Simplex Incident Manager
        "Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01

      Vulnerabilities

      • Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
        "Cisco on Wednesday announced patches for 15 vulnerabilities across its products, including critical- and high-severity flaws in Crosswork and Secure Workload. Crosswork version 7.2.1-SP was released with fixes for four critical-severity CVEs. Three of them, CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358, have a maximum severity rating (CVSS score of 10/10), while the fourth, CVE-2026-20359, has a near-max severity (CVSS score of 9.9/10)."
        https://www.securityweek.com/cisco-patches-critical-crosswork-secure-workload-vulnerabilities/
      • Critical Unauthenticated File Upload To RCE In Elementor Pro Plugin
        "This blog post is about an unauthenticated arbitrary file upload vulnerability in the Elementor Pro plugin that leads to remote code execution. The flaw lives in the Forms module’s File Upload field, where the extension check and the file-move step run in two separate loops with different handling of empty file entries. By submitting two file parts for the same field, an unauthenticated attacker skips the extension blocklist entirely and writes a PHP file into a public directory. Patchstack has issued mitigation rules to protect against exploitation of this vulnerability."
        https://patchstack.com/articles/critical-unauthenticated-file-upload-to-rce-in-elementor-pro-plugin/
        https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html
        https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/
      • Critical Zimbra RCE Flaw Now Actively Exploited In Attacks
        "CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). ZCS is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies. The Zimbra security team released version 10.1.20 on July 20 to patch the vulnerability (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled."
        https://www.bleepingcomputer.com/news/security/critical-zimbra-rce-flaw-now-actively-exploited-in-attacks/
        https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html
        https://www.securityweek.com/hackers-target-zimbra-servers-in-active-exploitation-campaign/
      • Solar Winds Part 2 Avoided: N-Able Passportal Vault Leak
        "N-Able's PassPortal extension, on Chrome and Edge allowed any site or iframe a user is presented with to gain complete, persisted access to the decrypted vault for up to 100 days. CVSS v4.0, base 9.4. Fixed within 24hrs. 73k+ affected weekly active users. v3.49.5 is vulnerable, v3.49.6 patched. N-able (formerly SolarWinds MSP) is publicly traded at ~$800M market cap. They provide cloud-based remote monitoring, management, and security platforms specifically designed for Managed Services Providers (MSPs) - and they have a password manager called PassPortal. N-Able's PSIRT were incredibly fast and cooperative throughout the process, giving us an account and publishing a fix within 24 hours of us reporting this to them."
        https://amibeingpwned.com/blog/solar-winds-part-2-avoided
        https://www.darkreading.com/vulnerabilities-threats/n-able-bug-password-vault-master-keys
      • Atlassian, Splunk Patch Dozens Of Critical, High-Severity Vulnerabilities
        "Atlassian and Splunk this week announced patches for over 250 vulnerabilities across their products, including dozens of critical- and high-severity flaws. On Tuesday, Atlassian published a Security Bulletin detailing 10 critical- and 162 high-severity issues in third-party dependencies, patched with fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira. Because the vulnerable libraries are used across multiple products, many of the patched security defects affect multiple products. Overall, the fixes appear to address approximately 109 unique CVEs."
        https://www.securityweek.com/atlassian-splunk-patch-dozens-of-critical-high-severity-vulnerabilities/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability
        CVE-2026-72530 TrueConf Server Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • Zero-Click Grok Data Theft: Cryptographic Context Injection Attack Leaks Chat Histories
        "A new attack technique we call Cryptographic Context Injection works around guardrails and gets attacker commands processed in a trusted context by shipping those instructions as cryptographically secure ciphertext and inducing the model to decrypt them inside its own code execution runtime. This lets attackers steal data using the access the AI system has, or modify the agent’s behavior, which we demonstrate against Grok and Gemini."
        https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/
        https://thehackernews.com/2026/08/new-cryptographic-context-injection.html
      • GHSA-864f-Rcv7-6rh4: Critical Type Confusion Vulnerability In Isolated-Vm
        "We discovered a critical vulnerability (GHSA-864f-rcv7-6rh4; pending CVE assignment) in isolated-vm, a widely used library for running untrusted JavaScript inside a V8 Isolate. A type confusion in ExternalCopy's handling of the transferList option lets code running inside the sandbox corrupt memory in the host process. Starting from nothing but a single ivm.Reference, the standard way hosts hand a sandbox any capability at all, we escalated the bug from a controlled-address crash all the way to hijacking the host's control flow, demonstrating a full guest-to-host sandbox escape."
        https://www.endorlabs.com/learn/ghsa-864f-rcv7-6rh4-critical-type-confusion-vulnerability-in-isolated-vm
        https://thehackernews.com/2026/08/isolated-vm-flaw-lets-sandboxed.html
      • CDN Tsunami Attack Abuses HTTP/3 Translation For Up To 350x DoS Amplification
        "Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server. The attacks, collectively named "CDN Tsunami," were evaluated against Alibaba, Baidu, Cloudflare, Amazon CloudFront, Fastly, and Tencent. All six were found susceptible to the bandwidth variant and five to the connection variant, with Cloudflare unaffected by the latter because it buffers the complete request before opening a connection to the origin."
        https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html
        https://arxiv.org/html/2607.26589v1
      • JFrog Artifactory Flaws Enable Software Supply Chain Attacks
        "Two vulnerabilities in JFrog Artifactory have been found which allow anonymous or low-privileged users to manipulate package metadata without modifying the underlying artifacts, creating a potential route to software supply chain compromise. Oligo Security reported the flaws to JFrog on June 25 and detailed them in research published on August 20. The findings cover CVE-2026-69106 (CVSS score 8.8), which affects the handling of the X-Orig-Client-Uri header, and CVE-2026-65922 (CVSS score 5.4), which allows writes into trusted .jfrog/ metadata paths."
        https://www.infosecurity-magazine.com/news/jfrog-flaws-software-supply-chain/

      Malware

      • One Adversary: Fraud Is a Network, Not a Payment
        "The hardest fraud to stop is the one the customer wants to make. In 2025, investment scams were the largest fraud loss category in both Australia and the United States, roughly $8.7 billion combined, with Australian losses of $837.7 million across more than 481,000 reports, US losses of $7.9 billion, average individual losses above $10,000, and the over-65s carrying more than a quarter of Australia’s total. In almost every case, the victim authorised the payment, often over their bank’s warnings. At the transaction, there was nothing to refuse. Behind aggregate numbers like these sit specific, organised operations, and Group-IB’s investigation of the ecosystem profiled two that show how the business works."
        https://www.group-ib.com/blog/one-adversary-fraud-network/
      • Post-DEF CON Phishing Uses Google Doc Apps Script To Deliver Malware
        "Large industry events like Black Hat and DEF CON create a target-rich environment for bad actors, with attendees exchanging new contacts, documents, invitations, and follow-up plans. Attackers are using this activity to make malicious outreach look like just another routine post-conference interaction. Fresh off the heels of "Hacker Summer Camp," there have been several reports of phishing campaigns that target attendees, with one of our own researchers being among those targeted by threat actors. In this case, on August 9, the X account @HartmansDoeke sent a direct message posing as CoinDesk's VP and Head of Marketing and asking for help with their upcoming conference. The account appears to use one person's image with another person's name. The message ultimately directed the recipient to a Google Doc featuring a custom sidebar designed to guide them through the execution of malware."
        https://www.huntress.com/blog/defcon-phishing-google-doc-malware
        https://www.infosecurity-magazine.com/news/def-con-attendees-persistent/
      • Rust Supply-Chain Attack: Arrayref, Internment, And Append-Only-Vec Poisoned By The Proc-Macro1 Build-Time Dropper
        "A compromised maintainer account and a same-day impersonator of one of Rust's best-known authors turned a routine cargo update into silent remote code execution. Three crates from the same owner were poisoned in 23 minutes (arrayref, internment, and append-only-vec), alongside six attacker-owned crates now deleted from crates.io. The malicious releases are gone, but the 07:11–09:25 UTC exposure window leaves an open question: who built during it? Verified timeline, IOCs, runtime detection, and remediation inside."
        https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
        https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/
        https://www.aikido.dev/blog/two-popular-rust-crates-arrayref-and-append-only-vec-compromised-in-supply-chain-attack
        https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/
        https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html
      • Manic: Blend Between Banking Malware & Spyware
        "The modern mobile threat landscape includes numerous malware families operated by individual threat actors and organised criminal groups, all competing for ways to infect victims as smoothly and inconspicuously as possible. Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features. Its targeting is strongly focused on Ukraine, covering Ukrainian banks, government and identity services, and messaging applications, while also extending to Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications."
        https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware
        https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html
        https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/
        https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html
      • UAT-10147: Chinese-Speaking Adversary Integrates Agentic AI Into Post-Compromise Operations
        "Cisco Talos identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology, and gaming sectors. The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale. UAT-10147 integrated AI-driven tooling into exploitation, reconnaissance, payload generation, validation, and persistence workflows. Talos observed AI-generated operational playbooks, exploit automation scripts, and troubleshooting logic supporting real-world intrusions. The actor employed a mixture of open-source offensive frameworks, including Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits to automate intrusion operations and establish persistence."
        https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
      • UAT-10147 Deploys SPECTRE: A Cross-Platform Implant With Linux Rootkit And BYOVD Capabilities
        "UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques. The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality."
        https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/
      • When AI Becomes The Lure: A Fake Gemini Installer Delivers Vidar
        "As organizations are increasingly adopting generative AI tools into their daily workflows, attackers are adapting their distribution methods accordingly too. As part of their day-to-day work, users are now searching for AI assistants, programming tools, browser extensions, desktop applications, and productivity integrations. Recent reports have highlighted campaigns that use fake AI software and AI-related installers to distribute malware and steal credentials [1]. Researchers have documented campaigns that exploit fake AI-themed websites and services to distribute information stealers and backdoors [2]. Security researchers have also observed attackers disguising malware as legitimate installers for AI software to increase the likelihood of victim interaction and execution [3]."
        https://www.darktrace.com/blog/when-ai-becomes-the-lure-a-fake-gemini-installer-delivers-vidar
        https://www.helpnetsecurity.com/2026/08/20/fake-google-gemini-installer-vidar-infostealer/
      • The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares Its Next Strike On Mobile
        "The zLabs team recently identified an updated variant of ToxicPanda, the Android banking Trojan known to have primarily targeted Europe, that introduces significant enhancements, including a comprehensive command set of 167 remote commands and substantially expands its targets globally. Among the newly added capabilities is a PIN theft mechanism targeting more than 140 banking and cryptocurrency applications. By abusing the Android Accessibility Service, threat actors can steal every UI element on the screen, alongside an overlay-based credential theft mechanism targeting 349 financial institutions, compared to the previous version, which targeted only 16 banking applications, the latest iteration demonstrates a significant expansion in targeting scope and capabilities. Several commands previously identified as unimplemented in Cleafy’s analysis are now fully operational, expanding the malware’s remote control and fraud capabilities."
        https://zimperium.com/blog/the-toxicpanda-never-sleeps-toxicpanda-2.0-prepares-its-next-strike-on-mobile
        https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html
        https://www.infosecurity-magazine.com/news/updated-toxicpanda-140-banking/
      • WeedHack Returns: How SEO Poisoning Is Leading Minecraft Fans To Malware
        "McAfee Labs’ latest investigation into the WeedHack malware campaign found that the threat has continued to evolve even after its original command-and-control infrastructure was disrupted by McAfee. Researchers identified multiple active websites still distributing WeedHack to gamers, often by impersonating legitimate Minecraft clients, offering paid tools for free, or using trusted platforms to make malicious downloads appear credible."
        https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-fake-gaming-websites-seo-poisoning/
      • Going With The Flow(s): Distinct Clusters Target Individuals Of Interest To Russia
        "Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additional two distinct suspected Russian clusters, UNC7005 and UNC5976, which conduct phishing, abuse OAuth flows, and/or deploy malware to victims. UNC7005 in particular is tied to the hospitality captive portal redirects reported on by Reliaquest and Microsoft. While each group conducts their campaigns differently, they all ultimately demonstrate a focus on abuse of legitimate authentication workflows to compromise accounts."
        https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia
        https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html
      • 77 Firefox Extensions Linked To Crypto Wallet And Credential Theft
        "The Socket Threat Research team is tracking 77 Firefox extension identities linked through code reuse, cloned extensions, deceptive marketplace descriptions, author-selected add-on ID patterns and domain-like suffixes, cryptocurrency-wallet impersonation, and version histories showing extension repurposing. Extension-level analysis confirms 40 as malicious. Another 37 form a coordinated multi-sport score-shell operation. Their analyzed builds contain no confirmed credential- or wallet-stealing payloads, but their deceptive functionality, shared publishing artifacts, and version histories indicate malicious intent."
        https://socket.dev/blog/firefox-crypto-wallet-theft
        https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html
      • Identity Abuse Through Trusted Communication Channels
        "Identity has become a primary security boundary for most organizations, reducing the ability to solely trust other boundaries once associated with corporate networks. Users authenticate to cloud services using enterprise identities that provide access to collaboration platforms, business applications and sensitive data. With the adoption of software-as-a-service (SaaS) on the rise, people are shifting to platforms for communication and collaboration."
        https://unit42.paloaltonetworks.com/communication-channel-identity-risks/

      Breaches/Hacks/Leaks

      • Genomics Testing Lab Notifies Nearly 310,000 Of Hack
        "Genomics testing firm Baylor Genetics is notifying nearly 310,000 people and counting about a June hack that compromised sensitive patient information including test results and employee data. The incident is the latest in a rash of attacks hitting medical laboratories, biotech and life sciences firms. Baylor Genetics has so far reported to several state attorneys general that nearly 250,000 Texans were affected, as well as nearly 57,000 citizens in Massachusetts and more than 2,600 residents of Vermont."
        https://www.bankinfosecurity.com/genomics-testing-lab-notifies-nearly-310000-hack-a-32618
      • Reverse Image Search Platform Exposed 9 Million Images
        "I recently discovered a publicly exposed database that was neither password-protected nor encrypted. The database contained approximately 9,042,977 image files totaling 450.2GB of data. The exposed records consisted primarily of facial images stored in folders labeled “faces” and “profiles.” In a limited sample of the exposed images I reviewed as part of the investigation, I observed facial images of adults, teens, and children. These included what appeared to be profile images, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or other identity verification purposes."
        https://www.expressvpn.com/blog/clarity-check-data-exposed/
        https://www.malwarebytes.com/blog/privacy/2026/08/9-million-images-of-peoples-faces-exposed-by-reverse-lookup-service

      General News

      • July 2026 Threat Trend Report On APT Groups
        "The July 2026 Threat Trend Report on APT Groups summarizes the trend in which state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks, account takeovers, cloud breaches, and social engineering techniques. Key targets include Microsoft 365, webmail accounts, cloud infrastructure, GitHub and development environments, VPN and remote access systems, mobile devices, and credentials stored in browsers."
        https://asec.ahnlab.com/en/95040/
      • AI Is Making Fraud Harder To Spot And Identity Harder To Prove
        "Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and account activity. Fraud used to be treated as an isolated event, such as a forged check, stolen credit card or false invoice. It has become a regular part of digital activity, appearing through phishing emails, scam texts, delivery notices, misleading ads and account alerts."
        https://www.helpnetsecurity.com/2026/08/20/experian-digital-identity-fraud-risks-report/
      • 8,539 Reasons To Rethink How Vulnerabilities Get Patched
        "The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. The increase adds pressure to a patching process that requires teams to decide which problems deserve immediate attention. A vulnerability’s severity score can help with that decision, but exposure and reachability also matter. A flaw on an internet-facing system can present a different security problem from one that attackers cannot readily reach."
        https://www.helpnetsecurity.com/2026/08/20/rapid7-vulnerability-patch-cycles-report/
      • Calling On Cyber Pros To Help Defend City Hall
        "A government agency I work with lost nearly a million dollars and never heard an alarm. No ransom note, no locked-up servers. Attackers slipped into a handful of staff email accounts, watched how the agency moved money for a couple of months, and then quietly rerouted a wire meant for an affordable-housing project. Nobody caught it until the money was already gone. This wasn't a federal department or a Fortune 500 company. It was a local housing authority, the kind of place that helps families make rent. And here's the part I keep coming back to: The breach isn't how the story ends."
        https://www.darkreading.com/cyber-risk/calling-on-cyber-pros-to-help-city-hall
      • Money And Mindset: The Two Biggest Roadblocks To Cyber Policing
        "Malware silently spread through a Texas law enforcement system—hidden inside body camera footage that police uploaded to the department server and then shared with county officials, prosecutors, and defense attorneys. As the compromised video traveled through the chain of command, the danger of putting highly sensitive data at risk only grew. That is one example that highlights how important it is for various arms of law enforcement to receive adequate cyber training, explains Justin Miller, associate professor of practice of cyber studies at University of Tulsa, and a retired senior special agent with the U.S. Secret Service."
        https://www.darkreading.com/cybersecurity-operations/money-and-mindset-the-two-biggest-roadblocks-to-cyber-policing
      • Surveillance – Everything You Wanted To Know, But Were Afraid To Ask
        "We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it. Nobody does anything without reason. So, organizations watch and track us for a purpose. That purpose is always for their benefit, not ours. But who are they? Why and how do they do it, and how many organizations do it? It may appear as if it is just an assault on our privacy, but it’s wider than that – the collected information is a powerful tool for further data theft, for targeting critical industries, and for disrupting governments."
        https://www.securityweek.com/surveillance-everything-you-wanted-to-know-but-were-afraid-to-ask/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 780f7e98-7adb-4a41-a354-774fd3fbfed2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตือนช่องโหว่ใน Zimbra ถูกใช้โจมตีจริง เสี่ยงรันคำสั่งบนเซิร์ฟเวอร์

      เตือนช่องโหว่ใน Zimbra ถูกใช้โจมตีจริง เสี่ยง.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand cfbdcc2b-ac1b-49d6-8ae5-cfa12d94dbcf-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แฮกเกอร์ยึดกล้อง Dahua กว่า 14,500 ตัว ในแคมเปญ CameraSwarm นาน 35 วัน

      แฮกเกอร์ยึดกล้อง Dahua กว่า 14,500 ตัว ในแคมเปญ CameraSwa.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5dbff306-b429-4936-9d41-6cf6f8809d3b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เหตุการณ์ข้อมูลรั่วไหลจาก CareCloud บริษัทไอทีด้านการแพทย์ ส่งผลกระทบต่อผู้ป่วยกว่า 3.7 ล้านราย

      เหตุการณ์ข้อมูลรั่วไหลจาก CareCloud บริษัทไอทีด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 56014f00-74af-4551-9f43-a7ba0d4566e1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เตือนช่องโหว่ Windows Task Host ถูกกลุ่ม Ransomware นำไปใช้โจมตี

      CISA เตือนช่องโหว่ Windows Task Host ถูกกลุ่ม Ransomware นำไปใช.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d4d88a7b-7759-4019-b397-b54f6a47dd65-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • GitLab ออกแพตช์ฉุกเฉินแก้ช่องโหว่ GraphQL ระดับ Critical กระทบ Self-managed Server

      GitLab ออกแพตช์ฉุกเฉินแก้ช่องโหว่ GraphQL ระดับ Critical .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 943c3bd8-27ae-4daf-a75a-d5b24757a072-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • กลลวงกลุ่ม Ransomware แอบอ้างว่าสามารถช่วยลบข้อมูลที่ถูกขโมยไปได้ แต่กลายเป็นการหลอกเรียกเงินซ้ำซ้อน

      กลลวงกลุ่ม Ransomware แอบอ้างว่าสามารถช่วยลบข้อ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e77540c2-0f19-4aa2-98e8-94199a1596b6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT