NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,477
    • กระทู้ 2,478
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 17 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a865c16d-98b2-4831-a134-de1fbb77e3b3-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 18 August 2026

      Government/Law/Policy

      • ETSI Launches Approval Process For 17 European Standards Supporting The Cyber Resilience Act
        "ETSI is pleased to announce the availability of the 17 vertical final draft standards developed in the framework of the EU Cyber Resilience Act (CRA) and currently under Public Enquiry. These standards aim to become Harmonised Standards, giving manufacturers a recognised way to demonstrate compliance with the legislation, the so-called “presumption of conformity”. The ETSI EN 304 xxx series standards on cybersecurity requirements have been submitted this summer to 41 member organisations across Europe, including the national standardisation bodies of the European Economic Area. They will be able to provide comments as part of the first phase of the approval procedure. ETSI’s societal partners ANEC (the European consumer voice in standardisation), ECOS (the European Environmental Citizens’ Organisation for Standardisation), ETUC (the European Trade Union Confederation), and SBS (Small Business Standards), collectively known as the Annex III Organisations, will also be able to comment on these standards."
        https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/
        https://www.infosecurity-magazine.com/news/etsi-proposes-17-cybersecurity/

      New Tooling

      • Hazmat: Open-Source Containment For AI Agents
        "Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configuration in your home directory that has accumulated over years. Hazmat gives the agent a home of its own and shares only the project directory you point it at. Your keys and credential folders sit outside what the session can reach."
        https://www.helpnetsecurity.com/2026/08/17/hazmat-open-source-ai-coding-agent-containment/
        https://github.com/dredozubov/hazmat

      Vulnerabilities

      • 40,000 WordPress Sites Affected By Authentication Bypass Vulnerability In User Profile Builder WordPress Plugin
        "On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder, a WordPress plugin with more than 40,000 active installations. This vulnerability makes it possible for unauthenticated attackers to log in as the user with ID 1, which is typically the site administrator, resulting in full administrative takeover of the site. The vulnerability is only exploitable on sites where the plugin’s Automatically Log In setting is enabled. Props to Supakiad S. (m3ez) who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program. This researcher earned a bounty of $975.00 for this discovery."
        https://www.wordfence.com/blog/2026/08/40000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-user-profile-builder-wordpress-plugin/
        https://www.infosecurity-magazine.com/news/wordpress-plugin-flaw-40000-sites/
      • 600,000 WordPress Sites Affected By Arbitrary File Upload Vulnerability In Forminator Forms WordPress Plugin
        "On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more than 600,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site compromise. The vulnerability is only exploitable on sites that have a form containing both a File Upload field and a Select field."
        https://www.wordfence.com/blog/2026/08/600000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-forminator-forms-wordpress-plugin/
        https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html
      • Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
        "GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on August 17, 2026, the critical patch release arrived outside the company's usual schedule of twice-monthly updates on the second and fourth Wednesdays, five days after a routine patch release that carried no critical-rated issues."
        https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html
      • Microsoft Working On Defender Patch For ShieldBreak Zero-Day
        "On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named "ShieldBreak." A security researcher who uses the "Nightmare Eclipse" handle disclosed this privilege escalation vulnerability after Microsoft released the August 2026 Patch Tuesday security updates. ​"Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding the new ShieldBreak zero-day."
        https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/
        https://www.bankinfosecurity.com/microsoft-faces-fresh-nightmare-eclipse-zero-day-a-32573
        https://www.malwarebytes.com/blog/bugs/2026/08/shieldbreak-bypasses-microsofts-patch-for-earlier-defender-flaw
      • Windows 11’s Strongest Security Defenses Can Be Bypassed Without a Screwdriver
        "Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. The attack, named “Download More RAM,” targets a small configuration chip found on Dual In-line Memory Modules (DIMMs), the RAM sticks inside most desktops and laptops. That chip stores information about the memory module, including its capacity and configuration. On several consumer memory modules, nothing stops software from rewriting critical parts of it."
        https://www.helpnetsecurity.com/2026/08/17/windows-11-security-bypass-research/
        https://www.usenix.org/system/files/usenixsecurity26-collins.pdf
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog
      • UNISOC T612 LPE
        "UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device chipsets. Formerly Spreadtrum, it serves major brands like Honor, realme, vivo, Samsung, and Motorola, with products in over 140 countries. A critical vulnerability has been identified in the Unisoc modem firmware that allows arbitrary code execution with kernel privileges from the modem context."
        https://ssd-disclosure.com/unisoc-t612-lpe/
        https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html
        https://www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modems
        https://www.infosecurity-magazine.com/news/unisoc-modem-flaw-rce-calls/
      • Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Through a Flaw In a GitHub Copilot–Assisted PR
        "As part of ongoing security research conducted through Snowflake’s HackerOne vulnerability disclosure program, Wiz Research’s "Red Agent"—an autonomous, AI-powered security research tool—identified a critical GitHub Actions workflow vulnerability in one of Snowflake’s public repositories. This incident highlights a new reality in software development: Critical vulnerabilities can still be introduced and approved within workflows involving AI coding agents, while autonomous AI security agents can rapidly discover and exploit them in the wild."
        https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug
        https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html
        https://www.theregister.com/security/2026/08/17/an-ai-failed-to-detect-a-bug-in-snowflakes-code-then-another-ai-agent-exploited-it/5288666

      Malware

      • C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
        "In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance, and deploying second-stage payloads. In this blog post, ThreatLabz provides a technical analysis of the identified C2Looper variants, including their network communication protocols and capabilities."
        https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2
      • Global Exploitation Of CVE-2026–59310 By Suspected Chinese-Nexus APT & Related CVE-2026–59309 Activity
        "QUIRSO’s Incident Response team recently investigated a VMware vCenter compromise that uncovered a coordinated, global exploitation campaign targeting CVE-2026–59310 as well as exploitation of CVE-2026–59309 by a possible different actor. Our investigation enabled us to map affected systems across numerous countries and identify evidence pointing to a Chinese-nexus advanced persistent threat. We continue to track the campaign as it develops. This article presents our current findings on its scale, victimology, infrastructure, tooling and attribution, while acknowledging that the assessment may evolve as new evidence emerges."
        https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
        https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html
      • The Gentlemen Ransomware: Inside One Of The Fastest-Growing Extortion Operations
        "The Gentlemen is a financially motivated ransomware-as-a-service (RaaS) double-extortion operation. Originally appearing as affiliate activity under other ransomware programs, the core operators established The Gentlemen as an independent brand in mid-2025 and began recruiting experienced affiliates with a 90% share of ransom proceeds. This generous affiliate share is one of several reasons why the group has been able to expand so quickly. As of this writing, The Gentlemen has claimed more than 750 victims worldwide, and it continues to add new victims at a steady pace. Multiple reporting sources now rank the group alongside Qilin as the most active ransomware groups by victim volume this year."
        https://blog.barracuda.com/2026/08/17/the-gentlemen-ransomware--inside-one-of-the-fastest-growing-rans

      Breaches/Hacks/Leaks

      • Massive Azure Exfiltration Campaign Exposes Millions Of Enterprise Records Via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl & Others)
        "A significant Azure exfiltration campaign is currently underway, driven by a threat actor actively selling massive enterprise employee databases. These extensive directories were reportedly downloaded directly from the organizations’ Azure/Entra portals utilizing compromised credentials. Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants."
        https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/
        https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
        https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/
        https://securityaffairs.com/197322/cyber-crime/mcdonalds-employee-data-appears-in-leak-seller-claims-1-7m-records-stolen.html
        https://www.bankinfosecurity.com/azure-breach-campaign-claims-mcdonalds-vodafone-as-victims-a-32578
        https://www.theregister.com/security/2026/08/17/crook-hawks-millions-of-records-allegedly-plundered-from-corporate-azure-tenants/5288305
      • Pokémon Center Data Breach Exposes Customer Info, Cancels Some Orders
        "Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. While CEVA's systems were compromised in the cyberattack, the exposed records belonged to Pokémon Center customers who submitted orders on the site. The company then shared this information with the logistics provider to fulfill and ship PokemonCenter.com orders."
        https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/
      • Philips And GE Investigating Clop Ransomware Data Theft Claims
        "Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. While a GE spokesperson said the company is aware of the claim and is "working to assess the potential issue," a Philips spokesperson confirmed its systems were breached but said the incident has been contained and didn't affect customers. "Philips has identified ​and contained an attempted cybersecurity compromise of a specific enterprise server related to ⁠internal data," Philips said in a statement shared with Reuters. "This has no impact on customer environments.""
        https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/
        https://www.bankinfosecurity.com/clop-claims-data-theft-from-more-than-40-companies-a-32581
      • Hack On Med Software Firm Hits Half Of Poland's Population
        "A hack into IT systems of MyDr, a Polish provider of electronic medical documentation software, has affected more than 12,000 healthcare facilities and nearly 19 million people in Poland, about half the country's population. Government authorities said they launched an investigation Aug. 12 into the alleged 2.5 terabyte data theft incident, in which cybercriminals appeared to have gained access into MyDr's IT environment no later than Aug. 6."
        https://www.bankinfosecurity.com/hack-on-med-software-firm-hits-half-polands-population-a-32580
        https://therecord.media/poland-probes-mydr-healthcare-software-breach
      • The LiteLLM Supply-Chain Attack — TeamPCP “SANDCLOCK” CI/CD Credential-Harvesting Campaign Via a Backdoored Trivy GitHub Action
        "Resecurity has acquired 152.5 GiB of data following a supply-chain security breach involving LiteLLM, exposing stolen corporate credentials and configuration data linked to thousands of domains. Analysis of the attacker's victim archive from the March 2026 LiteLLM supply-chain compromise (TeamPCP / “SANDCLOCK” stealer): 415,427 on-host secret-capture files harvested from GitHub Actions / CI-CD runners across 898 owners and 2,038 repositories — with the Trivy→LiteLLM attack chain, captured-secret composition, real masked evidence, and named victims."
        https://www.resecurity.com/blog/article/the-litellm-supply-chain-attack-teampcp-sandclock-cicd-credential-harvesting-campaign-via-a-backdoored-trivy-github-action
        https://securityaffairs.com/197377/hacking/litellm-supply-chain-attack-technology-banking-and-healthcare-the-most-affected.html
      • Irregular Details How a Naming Error Let AI Models Attack a Real Company
        "AI safety testing firm Irregular has published its account of an incident in which models being evaluated inside one of its testing environments took offensive security actions against real systems rather than the simulated targets they were meant to attack. The Israeli company, which last year raised $80 million in funding, has been in the news in recent weeks after it came to light that AI models it tested on behalf of OpenAI, Anthropic, and Meta escaped their test environments and carried out real-world attacks. Irregular’s core business involves partnering with major AI labs to stress-test models before they are released to the public, running controlled simulations designed to measure a model’s capabilities in vulnerability research and offensive cyber tasks."
        https://www.securityweek.com/irregular-details-how-a-naming-error-let-ai-models-attack-a-real-company/
        https://www.irregular.com/research/addressing-recent-incidents-ongoing-findings-and-path-forward
        https://therecord.media/irregular-ai-hacking-model-blog
        https://cyberscoop.com/irregular-ai-sandbox-escape-human-oversight/
      • Nearly 750k Had Financial Info, SSNs Leaked In South Carolina Loan Company Breach
        "Cybercriminals breached the cloud system of a debt consolidation loan company in May, stealing troves of sensitive financial information and personal data on about 750,000 customers. The company, Heights Finance, published a warning to customers last week about the data breach and told regulators in Texas on Friday that 734,828 people were affected. Heights Finance operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas and South Carolina."
        https://therecord.media/financial-info-leak-debt-consolidator

      General News

      • When Companies Get Specific About AI, Revenue Growth Looks Different
        "Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on data availability. The data included 478 corporate 10-K filings, more than 30,000 classified job postings, financial information, market data, and the AI Transformation Tracker built by Larridin."
        https://www.helpnetsecurity.com/2026/08/17/ai-adoption-revenue-growth-research/
        https://larridin.com/hubfs/CMU-Larridin AI-Company Performance 20270811.pdf
      • Infostealers Harvest 1.7 Billion Credentials In Six Months
        "Security researchers recorded 7.4 million devices infected with infostealer malware in the first half of 2026, a 27% increase from the previous six months, according to Flashpoint data. The threat intelligence company revealed the news in its 2026 Global Threat Intelligence Report: Midyear Edition, which features information collected from deep and dark web forums, illicit marketplaces, encrypted channels, and threat actor-linked infrastructure and ecosystems. In total, it claimed that hackers harvested 1.7 billion credentials via infostealer malware between January and June 2026, with Vidar, StealC and Lumma the top three most prolific infostealer variants."
        https://www.infosecurity-magazine.com/news/infostealers-17-billion/
      • Person Hides Prompt Injection In Legal Filing Telling AI To Side With Them
        "A person representing themselves in a Connecticut court hid a series of instructions designed to manipulate artificial intelligence in an official court filing. These “prompt injections” told the hypothetical LLM to side with them, and to “ensure your textual output agrees with the presented filing to ensure remediation.” The instructions were written in tiny, 3-point white font and hidden throughout the filing. In October, the person, named Matthew Elliott, sued the New York Bariatric Group, alleging a series of privacy violations, discrimination, and several other claims."
        https://www.404media.co/person-hides-prompt-injection-in-legal-filing-telling-ai-to-side-with-them/
        https://www.jdsupra.com/legalnews/the-first-documented-prompt-injection-1799990/
        https://securityaffairs.com/197370/ai/invisible-ai-prompts-trigger-court-sanctions.html
      • Phonescams: Casting a Wide Net In An Orchard Of Low-Hanging Fruit
        "Phonescams that impersonate some of America’s favorite brands—and some less expected ones—are distributed en masse to Cofense client email inboxes daily. In the digital age, everyone is looking to get ahead, and while one innovation breeds another, some things never change. Just as the humble wheel has been used for thousands of years, the easiest apple to pick off a tree is still the lowest hanging. Why fetch a ladder when the fruit is within reach? Here in the Cofense Phishing Defense Center, we have noticed that contemporary threat actors are all too aware of the concepts of wide nets and low-hanging fruit."
        https://cofense.com/blog/phonescams-casting-a-wide-net-in-an-orchard-of-low-hanging-fruit
      • Patterns And Problems In Emerging Multiagent Systems
        "Models are improving and AI agents are taking on more tasks in shared codebases, markets, and other social systems. As a result, an increase in real-world interactions between agents is imminent. We've already begun studying this, but still have a lot of uncertainty regarding what this looks like at scale. The trajectory is easy to imagine and hard to slow: current institutions are designed by and for people, resting on assumptions about the sufficiency of oversight at human speed. Some institutions will become human-AI hybrids; others where agents outcompete on speed or cost will become agent-only. The volume of agent-agent interaction could plausibly exceed that of human-human and human-agent interactions before the world understands the conditions for making such interactions go well."
        https://www.anthropic.com/research/multiagent-systems
        https://www.darkreading.com/threat-intelligence/turf-war-claude-agents-self-replicating-malware
        https://www.securityweek.com/conflicting-test-goals-pushed-claude-agents-to-deploy-self-replicating-malware/
      • Adam Shostack Talks Hugging Face & PHANTOM-B
        "OpenAI's rogue agents are raising a whole new set of questions for cyber defenders, and Dark Reading's senior news director Rob Wright sat down at the News Desk with threat modelling expert Adam Shostack to find out more. Shostack attended OpenAI's recent presentation on its findings in the wake of their AI agents going rogue, and he posed fundamental questions the industry will have to reckon with: namely, who is held liable when AI agents do real damage?"
        https://www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7e726480-ef24-4b7b-b7b6-b76eab99d0ab-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 17 August 2026

      Vulnerabilities

      • Chinese Loongson Processors Have Leaky Caches, Researchers Find
        "Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data. Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V. On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state."
        https://www.theregister.com/security/2026/08/13/chinese-loongson-processors-have-leaky-caches-researchers-find/5287137
        https://loongleakattack.com/
      • Unpatched GeoServer Zero-Day Targeted In Active Exploitation Attempts, Can Lead To RCE
        "A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @q1uf3ng on X. "GeoServer jsonArrayContains unauthorized SQL injection, and in the case of the sa [system administrator] database, it's naturally possible to achieve RCE," the researcher said."
        https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html
        https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/
        https://securityaffairs.com/197216/hacking/geoserver-zero-day-is-already-being-probed-thats-the-problem.html

      Malware

      • Hackers Exploit MacOS Screen Sharing Flaw To Deploy Monero Miner
        "The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900. Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases. The flaw allows network-based attackers to gain access without valid credentials."
        https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/
        https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html
        https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html
      • Max Severity SAP Commerce Cloud Flaw Now Targeted In Attacks
        "A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. Commerce Cloud (formerly known as SAP Hybris) is a cloud-based e-commerce platform used by online stores owned by high-profile global brands and large retailers. Tracked as CVE-2026-58231, this critical flaw stems from an improper authorization weakness in the core Data Hub Adapter extension for Commerce Cloud that threat actors without privileges can exploit in low-complexity attacks to execute arbitrary code."
        https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/
        https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
        https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html
      • ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked To Misconfigured Power Pages
        "Fortra Intelligence and Research Experts (FIRE) have developed specialist tooling to support certain customers when faced with ransomware and data extortion claims. We monitor for new disclosures, including public and dark web sources, to provide early alerting to customers and support investigations. As part of this process, we also see activity that is not directly related to customers. When there is a significant interest, and we have new intelligence to share, we aim to share information with the security community to aid understanding of ransomware and extortion actors and campaigns."
        https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
        https://www.infosecurity-magazine.com/news/exfilsquads-13-organizations/
      • AmnesiaStealer: a Multi-Stage Rust-Based MacOS Infostealer That Hijacks Chromium Browsers
        "Jamf Threat Labs discovers and investigates AmnesiaStealer, a multi-stage Rust-based macOS infostealer spread through a counterfeit GitHub download page that captures the login password, reaches for macOS bypasses Apple has already patched, and can hand the operator live, hidden control of the victim's Chromium browser to steal authenticated sessions."
        https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
        https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html
        https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/
        https://www.infosecurity-magazine.com/news/macos-infostealer-spread-clickfix/
        https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/
        https://securityaffairs.com/197190/malware/amnesiastealer-gives-attackers-live-control-of-victims-macos-browsers.html
      • APT Group HoneyMyte Upgrades CoolClient: The Backdoor Gets a Kernel-Level Windows Rootkit
        "CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent analysis by Trend Micro in 2023, CoolClient has continued to evolve. In 2025, we analyzed a newer variant that introduced clipboard theft and HTTP traffic interception for credential harvesting."
        https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
        https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html
        https://securityaffairs.com/197274/apt/mustang-panda-upgrades-coolclient-with-a-kernel-rootkit.html
      • Return Of The Cookie Monster
        "In Dough No! Revisiting Cookie Theft, we looked at how Chromium’s Application Bound Encryption (ABE) in Windows made cookie theft significantly harder. For operators, this meant they needed to inject into a browser process, utilize remote debugging, or install an extension to steal cookies. This blog post dives deeper how to enable the remote debugging protocol without having to launch it via the --remote-debugger-port argument. With the release of Chrome 136+, Google announced additional protections against stealing cookies via remote debugging. To enable the Chrome DevTools Protocol (CDP) an alternate --user-data-dir needed to be supplied with --remote-debugger-port causing the existing cookies to be abandoned as a new data directory would be used. These changes forced operators to think more carefully about their process context before stealing cookies."
        https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft/
        https://thehackernews.com/2026/08/chrome-devtools-technique-enables.html
      • Fake Zoom Installer Uses .NET Downloader To Deliver Overlord RAT On MacOS
        "Jamf Threat Labs recently identified a campaign using a fake Zoom installer to deliver a configured build of Overlord, an open-source remote access framework, hosted on attacker-controlled infrastructure. The downloader is a macOS ARM64 Mach-O binary named ZoomMeetings, built as a self-contained .NET 10 single-file application with the .NET runtime bundled inside. Rather than the Go or Rust we typically see in macOS malware, this downloader uses .NET, whose cross-platform support means the same codebase also targets Windows. Building macOS malware using the .NET framework is fairly uncommon, so naturally this caught our attention. Our curiosity led to a number of interesting finds that we'll share in this blog post."
        https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/
      • Large-Scale DDoS Attacks Disrupted Threema Secure Messaging Service
        "Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. ​Organizations using Threema On-Prem did not experience any issues because they rely on their own infrastructure. In a post-mortem report on Friday, the end-to-end encrypted instant messaging service said that the attacks were difficult to defend against because the threat actor constantly changed patterns."
        https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/
        https://securityaffairs.com/197353/hacking/ddos-attacks-cause-major-threema-outages.html
      • PATCHCORD: New Malware Cluster Targets Afghan Telecom And South Asian Critical Infrastructure
        "Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. Infrastructure pivoting uncovered SHEETCORD, a Go-based implant that builds on PATCHCORD's capabilities while abusing Google Sheets for C2 communication. The malware was actively distributed through a domain impersonating India's National Informatics Centre (NIC)."
        https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/
        https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html

      Breaches/Hacks/Leaks

      • Shell Investigates 'potential Incident' After Clop Data Theft Claims
        "Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. Shell is a British multinational energy conglomerate and one of the world's top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily. According to a recent post on Clop's dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans."
        https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/
      • RingCentral Data Breach Exposed Info Of 1.6 Million Accounts
        "The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. RingCentral is a cloud-based collaboration and communication platform used by over 600,000 businesses for services such as calling, messaging, and voicemail. The company disclosed the incident on July 28, revealing that its systems were compromised following what it described as a "sophisticated social engineering campaign.""
        https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/
        https://haveibeenpwned.com/Breach/RingCentral
        https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/
      • Scottish Govt Suffers Potentially Widening Data Breach At Prosecutor's Office
        "A contractor has leaked Scottish government employees' personal information, and the full scope of the breach may be far greater than what is currently being reported. On Aug. 13, Scotland's Crown Office and Procurator Fiscal Service (COPFS) — the government's public prosecution service and death investigation authority — disclosed that an unidentified external supplier had experienced a data breach. The breach affected some of its employees' personally identifying information (PII)."
        https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office
      • 7.3M Chess.com Records Leaked, And The Data Is Real
        "A 15.5 GB file containing 7,337,395 chess.com user records is being handed out free on two data-leak forums. It carries email addresses, usernames, real names, countries, ratings, subscription tiers and internal advertising-audience tags. Ransomnews verified the data against the file itself. It is genuine chess.com data, and it is days old, not a recycled dump. What it is not, on the evidence, is a break-in: every structural signal points to large-scale scraping of a non-public interface rather than a compromise of chess.com’s systems."
        https://ransomnews.com/chess-com-leak-7-million-2026/
        https://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html
      • LiteLLM Supply Chain Attack: Inside The AI Breach That Exposed 2,500+ Companies
        "New analysis published in August 2026 has overturned the original timeline of the LiteLLM supply chain attack. The well-known 40-minute PyPI window was not the beginning of the exposure. It was the final stage of a five-day collection run that started with the compromise of the Trivy scanner. Record-level data now maps exposure across more than 2,500 organizations and roughly 434,000 captured CI/CD files. SOCRadar’s analysis found that 95% of affected organizations appeared in the dataset before the malicious LiteLLM packages were published on March 24."
        https://socradar.io/blog/litellm-supply-chain-attack/
        https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/
      • France Investigates Tax Authority Breach After Hacker Claims 600,000 Victims
        "France’s tax authority has confirmed that hackers breached its information systems and extracted data on individuals and businesses. France’s Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate General of Public Finances, or DGFiP, in late June after stealing or misusing someone’s identity. The intrusion allowed the attacker “to view and extract data belonging to individuals and businesses,” according to the ministry."
        https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
        https://securityaffairs.com/197287/cyber-crime/sophisticated-cyberattack-exposes-data-of-678000-french-taxpayers.html
      • Uber Freight Keeps On Trucking After Extortion Crew Breaks In
        "Uber Freight says it is investigating a "data security incident" days after the Helix extortion group listed the company on its data leak site on August 6. Helix claims to have stolen nearly 1 million files from mailboxes, OneDrive accounts, the accounts receivable department, and other repositories. An Uber Freight spokesperson told The Register that the incident was under investigation but had not disrupted the company's daily operations."
        https://www.theregister.com/security/2026/08/12/uber-freight-keeps-on-trucking-after-extortion-crew-breaks-in/5286782
      • SafePal Data Breach Impacts 39,798 Customers, Stolen Info For Sale
        "Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. SafePal says the breach impacts customers who placed orders between March 2, 2025, and April 11, 2026, exposing their names, email addresses, shipping addresses, phone numbers, and purchase information."
        https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/

      General News

      • Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
        "Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers’ bank accounts. The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses of around €30 million ($34.6 million). While neither the Brazilian Federal Police nor Germany's BKA named the affected German financial institution, Brazilian media identified it as Commerzbank, a major European financial institution that generates more than €11.1 billion ($12.8 billion) in annual revenue."
        https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/
        https://therecord.media/investigation-into-banking-hack-leads-to-arrests-germany-brazil
      • Data Analyst Sent To Prison For Stealing Data, Extorting Employer
        "A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. Brightly is a Software-as-a-Service (SaaS) company formerly known as SchoolDude, which was acquired by Siemens in August 2022. Brightly employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide. 27-year-old North Carolina man Cameron Curry (also known as "Loot") was found guilty in March of orchestrating an "extensive cyber extortion scheme" targeting his employer."
        https://www.bleepingcomputer.com/news/security/data-analyst-sent-to-prison-for-stealing-data-extorting-employer/
      • Ransomware Threats In The Americas H1 2026: Dissecting The Regional Attack Patterns And Dominant Actors
        "The Americas carried the heaviest ransomware burden of any region on the planet in the first half of 2026. According to Cyble Research and Intelligence Labs (CRIL), North and South America combined experienced 2,188 documented ransomware attacks between January and June 2026. That single figure — 2,188 attacks — represents more than 57% of the 3,836 ransomware incidents CRIL tracked worldwide, making the Americas the undisputed center of gravity for global ransomware operations."
        https://cyble.com/blog/ransomware-threats-in-america-h1-2026/
      • What Boards Need To Know About Tech Risk
        "Most boardrooms are built to evaluate opportunity, growth initiatives, tech acquisitions, and operational improvements. The discussion centers on a familiar equation: investing in X to generate Y return. That mindset is essential for scaling a business. But it often creates dangerous blind spots in digital infrastructure. Unlike revenue-generating projects, many of the most important technology investments don't produce visible upsides."
        https://www.darkreading.com/cyber-risk/what-boards-must-know-tech-risk
      • The Hardest Part Of Agentic AI May Be Rebuilding The Business
        "Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research. About half of surveyed leaders say they understand how AI agents will affect their future operating model. Three main challenges limit wider adoption: the lack of a unified and accessible data foundation, limited trust in and governance of AI agents, and the cost and complexity of integration."
        https://www.helpnetsecurity.com/2026/08/14/deloitte-agentic-ai-readiness-gap-report/
      • Weak IAM Affects Up To 98% Of Cloud Environments
        "Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal agencies. More than two-thirds of midmarket organizations use multiple cloud providers, each with its own security model, terminology, and configuration settings. The same security issue can manifest differently across AWS, Azure, and Google Cloud, often requiring a different approach to identify and remediate, according to Intruder’s 2026 Cloud Security Index report."
        https://www.helpnetsecurity.com/2026/08/14/intruder-cloud-misconfiguration-trends-report/
      • Black Hat USA 2026: Will Vulnerability Discovery Eventually Decline In The AI Era?
        "The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months. It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes. An indication of the broader pressure facing cyber-defenders can be drawn from the sheer number of patches being delivered in Microsoft’s Patch Tuesday through the last four months: 169 CVEs in April, 118 CVEs in May, 571 CVEs overall in June (including 208 direct Microsoft CVEs) and another 622 vulnerabilities in July that included zero-days under active exploitation."
        https://www.welivesecurity.com/en/business-security/black-hat-usa-2026-vulnerability-discovery-decline-ai-era/
      • North Korean Remote Workers Are Infiltrating Government And Businesses: How To Expose Them Before Hiring
        "Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access."
        https://thehackernews.com/2026/08/north-korean-remote-workers-are.html
      • AI Can Find Bugs, But Human Knowledge Still Proves Them
        "Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also creates a new kind of pressure, because the industry can now produce more vulnerability-looking output than ever before."
        https://www.sans.org/blog/ai-can-find-bugs-but-human-knowledge-still-proves-them
      • Drop Something? Don’t Worry, Someone Caught It
        "Every day, tens of thousands of domain names expire and become available for registration. Some fade away and are never seen again. Others get a second chance. We refer to these as dropcatch domains: the domain was dropped, became available again, and someone caught it. This isn’t just our name; it’s widely used. There’s even an auction service called DropCatch[.]com. During the first half of 2026, we observed over 50k dropcatch domains a day in the gTLDs alone—when we add in various ccTLDs that number rises to around 65k. That’s an astounding number when you put it next to the total of new registrations every day. For the gTLDs, nearly 20% of all observed registrations are dropcatch. In other words, one of every five newly registered domains had a prior life, sometimes several."
        https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/
        https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html
        https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
      • AI Won't Solve Cybersecurity Burnout. Better Leadership Might
        "Cybersecurity has spent years talking about workforce shortages. More recently, AI has entered the conversation as a possible solution. It can help teams analyze alerts, identify threats, automate investigations, and complete routine tasks faster than ever. That shift is already underway. According to SANS workforce research, 74% of cybersecurity teams are changing structures and role assignments because of AI, with entry-level SOC and security analyst roles among the most affected. Yet workloads, complexity and stress continue to rise. The latest ISSA workforce study found that 68% of professionals believe their jobs have become harder over the past two years, and nearly half have considered leaving their current role."
        https://blog.barracuda.com/2026/08/14/ai-won-t-solve-cybersecurity-burnout--better-leadership-might

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7b745a34-7080-45b9-8405-28899a9c7f37-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบความพยายามใช้ประโยชน์จากช่องโหว่ SAP Commerce Cloud เสี่ยงรันโค้ดบนระบบ

      พบความพยายามใช้ประโยชน์จากช่องโหว่ SAP Commerce Clo.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 35acf675-b145-44b4-ab65-8d41d42e0cc2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CTM360 พบแคมเปญ Phishing สมัครงานกว่า 3,000 URL ใช้เทคนิค Browser-in-the-Browser ขโมย Credential

      CTM360 พบแคมเปญ Phishing สมัครงานกว่า 3,000 URL ใช้เทคนิค Bro.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9548d032-b9a5-41df-b758-4162bdc6eebc-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบกลุ่มผู้ไม่หวังดีกว้านซื้อโดเมนที่หมดอายุแล้ว เพื่อใช้เป็นฐานในการโจมตีทางไซเบอร์และแพร่มัลแวร์

      พบกลุ่มผู้ไม่หวังดีกว้านซื้อโดเมนที่หมด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand df49e788-349b-46f2-ad92-23c2e992b1aa-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 15 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 15 รายการ เมื่อวันที่ 13 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-225-01 AVEVA Enterprise SCADA
      • ICSA-26-225-02 Haiwell IoT Cloud HMI Gateway
      • ICSA-26-225-03 Johnson Controls Inc. Airwall
      • ICSA-26-225-04 Hitachi Energy APM Edge Product
      • ICSA-26-225-05 ANDRITZ HIPASE-250 and 250 SCALA
      • ICSA-26-225-06 Siemens RUGGEDCOM APE1808
      • ICSA-26-225-07 Siemens License Server (SLS)
      • ICSA-26-225-08 Siemens Desigo DXR and PXC Controllers
      • ICSA-26-225-09 Siemens Siveillance Video
      • ICSA-26-225-10 Siemens Parasolid
      • ICSA-26-225-11 Siemens Simcenter Femap
      • ICSA-26-225-12 Siemens Solid Edge
      • ICSA-26-225-13 Siemens LOGO! Soft Comfort
      • ICSA-26-225-14 Johnson Controls Metasys
      • ICSMA-26-225-01 Flow Neuroscience FL-100

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5659c9e0-8038-44d2-9544-47a194eab180-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 14 August 2026

      Healthcare Sector

      • Flow Neuroscience FL-100
        "Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits."

      Industrial Sector

      • Haiwell IoT Cloud HMI Gateway
        "Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges."
      • Hitachi Energy APM Edge Product
        "Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation."
      • Siemens Siveillance Video
        "Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions."
      • AVEVA Enterprise SCADA
        "Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization."
      • Johnson Controls Inc. Airwall
        "Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources."
      • ANDRITZ HIPASE-250 And 250 SCALA
        "Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations."
      • Siemens License Server (SLS)
        "Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version."
      • Siemens Desigo DXR And PXC Controllers
        "A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions."
      • Siemens Parasolid
        "Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions."
      • Siemens Simcenter Femap
        "Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version."
      • Siemens Solid Edge
        "Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions."
      • Siemens LOGO! Soft Comfort
        "Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version."
      • Johnson Controls Metasys
        "Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access."

      Vulnerabilities

      • WordPress 7.0.4 Patches Remote Code Execution Vulnerability
        "WordPress on Wednesday announced patches for a high-severity vulnerability that allows authenticated attackers to execute arbitrary code remotely. Tracked as CVE-2026-65640 (CVSS score of 8.8), the security defect can be exploited by attackers with Author-level user or higher permissions via malicious Postscript file uploads. According to WordPress’ advisory, the issue affects only installations that use Imagick and Ghostscript, as it was discovered in Ghostscript’s handling of certain embedded files. Successful exploitation requires that an attacker has file upload rights."
      • Fortinet Patches Authentication Flaws In FortiWeb And FortiManager
        "Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager. In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings. A remote, unauthenticated attacker could exploit the flaw, tracked as CVE-2026-26035, “to log in to the FortiWeb GUI/CLI with a random username and password,” Fortinet explains."
      • Microsoft Patches LegacyHive Windows Zero-Day Vulnerability
        "Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. The security flaw was disclosed by a security researcher who uses the "Nightmare Eclipse" handle in protest of Microsoft's bug bounty and vulnerability disclosure practices. Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released, claiming it exploits a security vulnerability in the Windows User Profile Service."

      Malware

      • Armored Likho Expands Its Cyber-Espionage Toolkit
        "In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage. We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal."
      • Akira Hits Safe Mode: Ransomware Rebooting Around EDR
        "Akira has become one of the most prolific ransomware operations and was the most active group we observed in 2025. Its affiliates have settled into a well-worn playbook: get in through an exposed VPN (usually SonicWall), pivot to the domain controller, enumerate Active Directory, stage and exfiltrate data, then detonate all within a few hours. Huntress has documented that playbook in depth: from the active exploitation of SonicWall SSL VPN appliances as an initial-access vector, to a recent case where an affiliate spun up a brand-new virtual machine on the victim's hypervisor specifically to run the encryptor somewhere Huntress wasn't installed."
      • Jewelbug: APT Group Runs Espionage And Crypto Fraud Operations Side By Side
        "A months-long investigation by the Symantec Threat Hunter Team has produced unprecedented visibility into the activities of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking into government ministries across Asia and the Middle East while quietly running a cryptocurrency fraud business on the side. The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel. Jewelbug’s commercial arm is tied to a known registered company in Hunan Province, China. The group has developed five generations of command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers and network devices, all of it feeding a single database of victims. That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims."
      • Dissecting The JWR Phishing Framework
        "JWR is a phishing framework capable of harvesting complete payment card data, login credentials, and personally identifiable information (PII) documents and images in real time. The client-side engine of the framework impersonates login, and checkout flows of several payment gateways, including Shopify, PayPal, Apple, Klarna, and banks, while allowing the operator to stealthily control the victim session through an AES-CTR encrypted WebSocket channel. The client engine architecture is divided into a Host Bridge module that relays commands into a phishing inline frame (iframe) and a Vue.js victim application that renders across 44 phishing pages, streams the victim's keystrokes to the actor as they are typed, and carries out more than 40 distinct instructions issued from the command-and-control (C2) console. The data exfiltration schema is a cvvform object that includes fields such as credit card number, CVV, PIN, expiry date, Social Security Number (SSN), passport or ID images, two-factor authentication (2FA) codes, website logins, PayPal credentials, and device fingerprint."
      • Multi-Functional Linux Botnet “Evooo1Bot”
        "FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary. While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities. Telemetry from its command-and-control infrastructure indicates that Evooo1Bot has been actively targeting Internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions. In this article, we provide a detailed analysis of Evooo1Bot’s modular architecture and operational features."
      • How To Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign
        "Organizations increasingly rely on GitHub to develop and store proprietary source code, internal documentation, and other software assets. This makes GitHub Personal Access Tokens (PATs) an attractive target for attackers, as a compromised token can provide access to private repositories and expose secrets such as cloud credentials, API keys, and private keys that may enable further compromise. Recently, the Wiz Customer Incident Response Team (CIRT) investigated a coordinated campaign in which compromised GitHub PATs were used to conduct repository reconnaissance and mass repository exfiltration across multiple organizations. Active from mid-May through early June 2026, the campaign progressed through several distinct stages, from reconnaissance and access validation to large-scale repository cloning and follow-on attempts to leverage exfiltrated credentials."
      • Top 10 Phishing Kits Used By Cybercriminals
        "Phishing kits have turned credential theft into a scalable service by packaging fake login pages, hosting, traffic filtering, victim management, and technical support into ready-made platforms. Advanced services such as Tycoon2FA, EvilProxy, and Sneaky 2FA can also intercept session cookies and bypass MFA methods that are not phishing-resistant, while platforms such as Darcula and Telekopye focus more heavily on smishing and consumer fraud. This article examines ten prominent platforms selected for their documented use, technical influence, current relevance, and value to defenders. It is not a strict ranking, and disrupted services are identified accordingly."

      Breaches/Hacks/Leaks

      • Trezor Discloses Data Breach Affecting Nearly 14,000 Customers
        "Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked. During the incident, the attackers gained access to customers' order data, including their full names, shipping addresses, email addresses, and phone numbers. As the company explained in a Thursday blog post, the resulting data breach affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026."
      • Exposed AWS Access Key Linked To Data Breach Affecting 1500+ UK Charities
        "A compromised AWS access key was the likely root cause of the cyber-attack on CRM provider Beacon, which has exposed personal information held by around 1500 UK charities. The software provider said in an August 12 incident update that the access key was potentially exposed in public Javascript build artifacts. This suggests an error was made in the course of software development. Beacon has assessed that the attacker used these valid credentials to access and download all data contained within the CRM platform, including attachment files, thereby impacting its entire 1500-strong customer base of charitable organizations."
      • INC Ransom Targeted 24 Law Firms, But Only 10 Are Listed
        "INC was on an encryption streak against US law firms in March 2026. SOCRadar identified 24 individualized extortion sites, hosted across two IP addresses, that we assess with high confidence are tied to INC Ransom. Each one is built for a specific US law firm, complete with its own countdown timer and highly likely shared with the victim firm’s customers to increase the pressure. Cross-referencing those 24 firms against INC’s known leak site months later, roughly 58% (14 of 24) do not appear there, while 42% (10 of 24) are listed."

      General News

      • Ukraine Shuts Down 94 Fraudulent Call Centers, Seize Millions In Cash
        "Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. The operation occurred this week, and police officers conducted a total of 411 searches following an investigation that involved the National Police, Ukraine's Security Service, the Prosecutor General’s Office, and the German police. According to the Ukrainian police, the fraudsters ran various schemes to obtain money from victims or gain access to their bank accounts."
      • Ransomware Didn’t Slow Down In Q2 2026. It Just Spread Out.
        "Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it."
      • PQC In Plaintext: Google Cloud’s Post-Quantum Cryptography Roadmap
        "Securing infrastructure and services against a future cryptographically-relevant quantum computer has been a goal for Google for a decade, and we’ve dedicated ourselves to help developers by advancing open standards that can benefit everyone. As post-quantum cryptography (PQC) has matured, we’ve been rolling it out in our infrastructure for internal and customer-facing services. Today, we're sharing our updated Google Cloud roadmap to migrate to PQC by 2029."
      • Germany Moves To Give Spy Agencies Hacking And Sabotage Powers
        "Germany’s cabinet approved legislation Wednesday that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era. Chancellery chief Nina Warken said the new powers could allow the agencies to substitute faulty components into deliveries, use cyber operations to sabotage drone factories or chemical weapons laboratories and disable servers run by hostile state-sponsored hackers and disinformation operators."
      • Trump Taps Cyber Firms To Go On Offensive Against Criminals
        "The Trump administration will allow private companies to launch attacks on cybercrime organizations, according to a presidential memorandum released late on Wednesday. The firms will partner with the Justice and Homeland Security departments on offensive operations and surveillance targeting “transnational cybercrime, fraud, and other predatory schemes against American citizens.” “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [Transnational Criminal Organizations] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memorandum said."
      • Apple Sends New ‘Threat Notification’ Alerts Over Mercenary Spyware Attacks
        "You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." Some users on Reddit are reporting that they received these alerts today after Apple sent out a new batch of threat notifications on August 13, but the feature itself is not new."

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) af0a2506-b6c9-422b-817f-717d1773a477-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • WordPress ออกแพตช์แก้ช่องโหว่ RCE ผ่านการประมวลผลไฟล์ภาพ

      WordPress ออกแพตช์แก้ช่องโหว่ RCE ผ่านการประมวลผล.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 490dd133-1909-45a2-8893-39d6a3b74df6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CEVA Logistics ถูกโจมตีทางไซเบอร์ กระทบคลังสินค้าและการจัดส่งในยุโรป

      CEVA Logistics ถูกโจมตีทางไซเบอร์ กระทบคลังสินค้าแ.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f073fcb3-5dd4-4b3c-b97d-f4c03805404b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ใหม่บน Android สามารถขโมยข้อมูลบัตรเครดิต และแอบทำธุรกรรมทางการเงินได้

      พบมัลแวร์ใหม่บน Android สามารถขโมยข้อมูลบัตรเ.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 213bcaf4-c5a4-4304-baac-18b0dbd2dce9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Zoom แก้ไขช่องโหว่ Zero-click ในฟังก์ชัน Annotation เสี่ยงรันโค้ดบนอุปกรณ์ผู้ใช้งาน

      Zoom แก้ไขช่องโหว่ Zero-click ในฟังก์ชัน Annotation เสี่ยงร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c4a51dce-0761-46e8-af4c-dadbc01394c8-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ExfilSquad เพิ่มรายชื่อเหยื่อใหม่ ใช้ Torrent เผยแพร่ข้อมูลที่ถูกขโมยจาก Cloud Portal

      ExfilSquad เพิ่มรายชื่อเหยื่อใหม่ ใช้ Torrent เผยแพร่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ffefb567-32b2-4e43-996b-8da747731463-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Google เผย Chrome บน Android บล็อกการแจ้งเตือนอันตรายมากกว่า 7 พันล้านครั้งต่อวัน

      Google เผย Chrome บน Android บล็อกการแจ้งเตือนอันตรายมา.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7c62d5d5-04f2-462c-9ea2-ae62c5a68ca5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 13 August 2026

      Industrial Sector

      • Rush To Build Data Centers Leaves OT Security Behind
        "In the rush to get servers on the ground, and new compute up and running, especially to cater to the artificial intelligence boom, data center owners have neglected security and left vulnerable operational technology devices dangerously close to the public internet, according to experts and recent research. Total U.S. capital expenditure on data centers is expected to top $700 billion this year, according to Moody's Investor Services, as tech giants and their smaller rivals race to power ever larger and more complex large language models and meet the predicted mushrooming demand from business. Over the next five years, predicts market intelligence firm Industrial Info Resources, data center developers and big tech firms plan to start construction on 2,913 data centers at a cost of about $2.4 trillion by 2030."
        https://www.bankinfosecurity.com/rush-to-build-data-centers-leaves-ot-security-behind-a-32538
      • ICS Patch Tuesday: Vulnerabilities Fixed By Siemens, Schneider, Phoenix Contact
        "Industrial giants Siemens, Schneider Electric, and Phoenix Contact have published August 2026 Patch Tuesday advisories to inform customers about vulnerabilities found in their ICS products. Siemens has published 10 new advisories. One covers a maximum-severity missing-authentication vulnerability in Simatic IoT2050 Advanced devices. A remote, unauthenticated attacker can exploit it to execute arbitrary code on the underlying server with elevated privileges. A critical code execution vulnerability has also been fixed by Siemens in the Siveillance Video Management Servers."
        https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact-2/
      • Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack
        "Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes. While the reported activity specifically references Rockwell Automation/Allen-Bradley MicroLogix PLCs, the targeting is not necessarily limited to these products, and other internet-facing PLCs may also be at risk."
        https://fortiguard.fortinet.com/threat-signal-report/6498

      Vulnerabilities

      • Adobe Patches Critical Magento Account Takeover (APSB26-92)
        "Adobe has released isolated security patches for APSB26-92 for Adobe Commerce and Magento Open Source. The update fixes seven vulnerabilities. Five are rated Critical, including CVE-2026-71362, an unauthenticated customer account takeover with a CVSS score of 9.1. Exploitation needs no existing account, administrator privileges or user interaction."
        https://sansec.io/research/adobe-commerce-account-takeover-apsb26-92
        https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts/
      • Ivanti EPM Update Patches Remotely Exploitable Flaws
        "Enterprise software company Ivanti on Tuesday announced patches for four vulnerabilities in Endpoint Manager (EPM) and Neurons for MDM. The EPM update addresses three high-severity bugs, including two that could be exploited by remote, unauthenticated attackers. Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections."
        https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/
      • SonicWall Patches Critical Vulnerabilities In Discontinued GMS Platform
        "SonicWall on Tuesday announced patches for eight vulnerabilities across two products, including critical-severity remote code execution (RCE) bugs. The cybersecurity firm rolled out fixes for six security defects in Global Management System (GMS), its centralized management, monitoring, and reporting platform that was retired in October 2025. Per SonicWall’s advisory, two of the flaws, namely CVE-2026-66147 (CVSS score of 9.4) and CVE-2026-66145 (CVSS score of 9.1), deserve special attention, as both could allw remote, unauthenticated attackers to execute arbitrary code."
        https://www.securityweek.com/sonicwall-patches-critical-vulnerabilities-in-discontinued-gms-platform/
      • New Microsoft Defender 'ShieldBreak' Zero-Day Grants SYSTEM Privileges
        "A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later. However, cybersecurity expert Kevin Beaumont, who also published ShieldBreak exploitation detection queries for Microsoft Defender for Endpoint, said that the two exploits work very differently."
        https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges/
        https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html
        https://securityaffairs.com/197063/hacking/shieldbreak-new-windows-zero-day-bypasses-microsofts-rogueplanet-patch.html
      • Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
        "Intel and AMD on Tuesday announced patches for a total of more than 80 vulnerabilities across their products. Intel has published 42 new advisories covering 72 vulnerabilities. The company patched several high-severity flaws in PROSet/Wireless WiFi software that could allow an attacker to escalate privileges or conduct a denial-of-service (DoS) attack."
        https://www.securityweek.com/chipmaker-patch-tuesday-intel-amd-fix-over-80-vulnerabilities-combined/
      • OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
        "A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing, even handed to a weaker model in the same provider family to make it reveal the hidden content."
        https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html
        https://arxiv.org/abs/2608.09867

      Malware

      • Active Exploitation Of CVE-2026–59310: 361 Victim IPs Across 47 Countries
        "QUIRSO’s Threat Research team is tracking an active exploitation campaign targeting internet-accessible VMware vCenter systems. Based on evidence collected during a recent incident response engagement, we assess that a suspected advanced persistent threat (APT) actor is exploiting CVE-2026–59310 and using reverse SSH to maintain access to compromised systems. CVE-2026–59310 is a critical directory-traversal vulnerability in the VMware vCenter Syslog server. According to Broadcom, an attacker with network access to vCenter may exploit the vulnerability to execute arbitrary code."
        https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff
        https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
      • The “City-Forum” Campaign - An Advanced Attacker Is Targeting Salesforce And ServiceNow Instances Worldwide
        "Reco is tracking an ongoing campaign we've named the City-Forum Campaign, after a domain tied to the threat actor's IP (more on that below). A single server is pulling records out of Salesforce Experience Cloud sites and ServiceNow (SNOW) Service Portals, from infrastructure that has been standing since March 2025. In the last year, we've seen many threat actors that use Aura enumeration against over-permissioned Salesforce guest users, for example ShinyHunters. This actor is different. Except for Aura, the attacker reaches Salesforce Lightning Web Runtime (LWR) sites through the UI-API, a data layer we have not seen any public tool or write-up about, and it hammers a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open source tools."
        https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
        https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attacks-target-salesforce-servicenow-portals/
        https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow
        https://www.securityweek.com/stealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset/
        https://www.helpnetsecurity.com/2026/08/12/salesforce-servicenow-guest-user-exposure/
      • 737 Chrome VPN Extensions Linked To Brand Impersonation And Browser Traffic Redirection
        "Socket's Threat Research Team identified a campaign of 737 free VPN and proxy extensions published across at least 40 Chrome Web Store developer accounts, 274 of which impersonate 66 established VPN and privacy brands, that route the user's entire browser session through SOCKS5 proxies operated by a single provider. Socket analyzed the code of 525 of them, 522 from bulk retrieval and 3 more found during store enumeration; the remaining 212 had been removed from the store before collection and were recovered at listing level only. 520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure."
        https://socket.dev/blog/chrome-vpn-extension-impersonation
        https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html
        https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy/
      • FBI: Hackers Target Online Accounts To Steal Nude Photos
        "The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. As the law enforcement agency explained in a public service announcement published this week, the attackers may use the stolen content to blackmail the victims or try to sell it on criminal marketplaces. They may also share the victims' personal information (including names, dates of birth, emails, phone numbers, and social media usernames) with other criminals, who can use it to pressure them into providing additional private images and videos through sextortion."
        https://www.bleepingcomputer.com/news/security/fbi-warns-of-hackers-targeting-online-accounts-to-steal-explicit-photos/
        https://www.ic3.gov/PSA/2026/PSA260810
        https://therecord.media/social-engineering-hackers-explicit-photos-fbi-alert
      • Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
        "On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script. A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administrator. The vulnerability is due to several issues in the JWT token validation pipeline."
        https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
        https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/
        https://www.securityweek.com/sharepoint-vulnerability-exploited-shortly-after-poc-release/
      • You're Invited To Get Phished! Why Invitation-Themed Emails Remain Effective
        "Threat actors are weaponizing party invitation-themed emails to steal credentials and install malware on victims’ machines. Cofense Intelligence has observed a sustained rise in phishing campaigns disguised as event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliver credential-harvesting login pages and remote access tools that give threat actors persistent control of a victim’s machine. The same link can fingerprint the recipient’s device and deliver different payloads to desktop and mobile users simultaneously, expanding the reach of each campaign without additional effort. The technology behind these campaigns has evolved, but the underlying lure has not. People are naturally curious about invitations, and attackers continue to exploit that instinct."
        https://cofense.com/blog/you-re-invited-to-get-phished!-why-invitation-themed-emails-remain-effective
      • Inside a Multi-Agent AI Framework Used To Compromise Government Entities In Asia
        "What follows is but one concrete example of what appears to be a near-autonomous attack, running off readily available harnesses and models and aimed at a nation state. Details on the attack were initially shared with the Financial Times. In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure. It spells out one thing loudly - the cost of running a competent attack has collapsed, but the cost of defending against one has not."
        https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia
        https://cyberscoop.com/near-autonomous-ai-attack-government-target-taiwan/
        https://securityaffairs.com/197079/apt/china-linked-hackers-use-ai-agents-in-autonomous-attack-on-taiwan.html
      • Gone With The WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
        "Contactless payment fraud has moved from a theoretical risk to an operational one, and the scale is now visible in both industry and regulatory reporting. The European Payments Council’s 2025 Payment Threats and Fraud Trends report identifies NFC relay fraud — and the related “Ghost Tap” technique — as a rising category, noting it frequently overlaps with remote access scams and results in unauthorized transactions and a complete loss of control over funds, with victims sometimes unknowingly drawn into money laundering as a result. The scale behind that assessment shows up clearly in independent telemetry: NFC-based attacks on Android devices rose 188% in the first four months of 2026 compared to the same period in 2025, with 35,600 attacks blocked in that window alone, up from over 12,300 a year earlier (Kaspersky); this followed a more than 35-fold increase in NFC-related attacks recorded in the first half of 2025 compared to the second half of 2024 (ESET)."
        https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
        https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/
        https://www.infosecurity-magazine.com/news/windrelay-nfc-relay-spynote-rat/
      • CopyEscape: Taking Over Docker Hosts With Docker Cp
        "Imperva Red Team uncovered CVE-2026-17106, a container-to-host arbitrary file-write vulnerability in Docker’s docker cp command. Docker later confirmed that the same CVE also affected sbx cp when copying files out of Docker Sandboxes. A malicious container or sandbox could exploit the copy process to create or overwrite files outside the destination selected by the user, potentially enabling code execution on the machine running the Docker CLI."
        https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp/
      • Dragon Breath (APT-Q-27): RONINGLOADER And Gh0st RAT Explained
        "Dragon Breath, also known as APT-Q-27and Golden Eye Dog, is a Chinese cybercrime APT first observed in 2020, targeting Chinese-speaking users and organizations across the Asia-Pacific region, including China, Hong Kong, Taiwan, Singapore, Japan, and the Philippines, with a focus on online gambling and financial services. Dragon Breath stands out for layered execution and defense evasion, combining trojanized installers with double-clean-app DLL side-loading, signed kernel drivers, Protected Process Light abuse, thread-pool process injection, and malicious code-signing. Its recent RONINGLOADER chain also deploys a modified Gh0st RAT over WebSocket-based C2 while actively disabling Windows Defender and regional endpoint security tools."
        https://www.picussecurity.com/resource/blog/dragon-breath-apt-q-27-roningloader-and-gh0st-rat-explained
      • ClickFix Campaign Abuses Deno Runtime For Infostealer Delivery
        "Counter Threat Unit™ (CTU) researchers investigated a June 2026 campaign in which threat actors used the Deno JavaScript runtime as a core execution mechanism within a ClickFix-driven intrusion chain. On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures that prompted users to execute a clipboard-delivered PowerShell command. This command initiated an MSI-based staging process that installed Deno and enabled retrieval and execution of remote JavaScript. CTU™ analysis indicates that Deno functioned as a key element supporting payload delivery, follow-on tasking, and persistence."
        https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery
      • Inside a Russian-Speaking Operator's Toolkit For Compromising Ukrainian IP Cameras
        "In late May 2026, Hunt.io Attack Capture™ identified an open directory on 89.208.97[.]165 containing files pointing to the compromise of a Ukrainian e-commerce site. The intrusion itself, through credential theft and SQL injection, is only the starting point. Bash history and custom scripts recovered from the directory show the operator turned that access into a proxy server, and then used password spray attacks and attempted web shell deployment against Ukrainian government and military sites. During our investigation, we identified a custom platform built to find, exploit, and catalog internet-exposed IP cameras."
        https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit

      Breaches/Hacks/Leaks

      • Ransomware Attack Disables Canadian Hospital's Doors, HVAC
        "A Canadian hospital is dealing with a ransomware attack on its facility management systems that has affected the building's doors and heating, ventilation and air conditioning equipment. Some experts said the incident underscores growing cyberthreats involving operational technology in healthcare. The attack this week on Manitoba, Ontario's largest hospital - Winnipeg's Health Sciences Centre, which is a facility operated by Shared Health, is under investigation, a Shared Health spokesperson told ISMG."
        https://www.bankinfosecurity.com/ransomware-attack-disables-canadian-hospitals-doors-hvac-a-32535
      • Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
        "Colombia's Ministry of Justice confirmed that a ransomware attack struck part of its technology infrastructure and degraded several public-facing services on Aug. 2, just five days before the nation's presidential handover. The attack, which disrupted some services around illicit-drug monitoring and legal processes, came a day after Colombia's national CERT (ColCERT) published a threat intelligence warning that ransomware groups had increased their focus on the country. While some media reports suggested that data had leaked during the Ministry of Justice compromise, then acting Minister of Justice Cielo Rusinque denied that any information had been stolen, during a Spanish-language news interview."
        https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition
      • 2,500+ Companies And 434,000 CI/CD Pipelines Exposed In The Largest AI Supply Chain Breach Of 2026
        "In March 2026, the threat actor group TeamPCP orchestrated what is believed to be the largest supply chain attack targeting AI infrastructure by compromising LiteLLM. CloudSEK Threat Intelligence was able to get access to the victim information and is disclosing the details of all the impacted victims . We are sharing this openly so that every affected organization can act proactively The threat is still live: the FBI's July 2026 FLASH advisory (FLASH-20260702-01) warns that affiliated actors are likely to weaponize the harvested credentials long after the original intrusion, which means further supply chain attacks remain a real possibility. Early awareness is the strongest defense; knowing you were impacted lets you rotate credentials, close the exposure, and harden before the next campaign hits."
        https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines
        https://exposure.cloudsek.com/ai-supply-chain-incident
        https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html
        https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/
      • Three Intrusions At UK Criminal Records Office Went Undetected For Two Years
        "Britain's criminal records office has been reprimanded by the country’s data protection regulator after being repeatedly breached over nearly two years, exposing the personal data of thousands of people including victims of domestic violence. The Information Commissioner’s Office (ICO) announced in the reprimand notice Wednesday that it was censuring ACRO Criminal Records Office over a range of security shortcomings, among them alerts from antivirus software going unread and a critical system left unpatched for nearly four years."
        https://therecord.media/uk-criminal-records-office-acro-data-breaches

      General News

      • July 2026 Cyber Threats Surge: Ransomware Attacks Double Year Over Year As GenAI Data Exposure Widens
        "July’s cyber threat landscape was shaped by pressure across multiple fronts. Global cyber attacks continued to rise, ransomware activity broke from the more stable pattern seen earlier in the year, and GenAI exposure became a clearer operational risk as employees used more tools and generated more prompts across the enterprise."
        https://blog.checkpoint.com/security/july-2026-cyber-threats-surge-ransomware-attacks-double-year-over-year-as-genai-data-exposure-widens/
      • Walmart Leaders Transform Security Operations Without Going Bananas
        "As the world's largest retailer, Walmart knows a thing or two about scale. It sells more bananas than any grocer, employs more than 2 million people across 19 countries, and generates more than $700 billion in annual revenue. And like all large companies, it's also in the crosshairs of cyber adversaries, so it's imperative that its leadership team understands the risks and buys into a mitigation plan."
        https://www.darkreading.com/cybersecurity-operations/walmart-leaders-transform-security-operations-without-going-bananas
      • Split-Second Deepfake Glitch Blows Digital Certificate Fraudster’s Cover
        "Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the police, the man made 38 attempts using this method on more than 30 citizens. Police haven’t said how many of those attempts succeeded before the scheme was uncovered. The National Police said the investigation started after a company that issues electronic certificates flagged a string of suspicious verification requests."
        https://www.helpnetsecurity.com/2026/08/12/deepfake-video-identity-verification-fraud-arrest-spain/
      • Post-Quantum Migration Gets Harder When Every User Holds a Key
        "In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break old size assumptions in IPsec, SSH, TLS and libp2p, why migrating user keys makes blockchains hard to upgrade, and what a silent quantum break would look like from outside. He also gives the argument for funding work whose payoff stays invisible."
        https://www.helpnetsecurity.com/2026/08/12/christopher-smith-quantus-post-quantum-migration/
      • 338 Million Attack Simulations Reveal The State Of Enterprise Defense
        "First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones. This data, and a lot more, comes straight from the newly published Blue Report 2026, the fourth annual comprehensive study from Picus Labs. Based on more than 338 million attack simulations run in real production environments in the first half of 2026, the report measures how enterprise prevention and detection actually performed against real attacks, from what controls stopped at the perimeter to what attackers can achieve once they’re inside."
        https://www.helpnetsecurity.com/2026/08/12/picus-security-blue-report-2026/
        https://thehackernews.com/2026/08/enterprise-defenses-recovered-at-edge.html
      • AI Deployments Are Stretching Enterprise Security To Its Limits
        "CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according to NetFoundry’s 2026 State of Secure AI Access survey. Organizations are under pressure to secure AI deployments, particularly in the retail and travel, healthcare and pharmaceuticals, and technology sectors. AI-related risks are now a top concern for security leaders. Only 15% of respondents said they were very confident their existing security tools could adequately protect AI deployments. Confidence was lower for CISOs."
        https://www.helpnetsecurity.com/2026/08/12/netfoundry-securing-ai-deployments-report/
      • NIST Seeks Public Input On AI-Ready NVD Modernization
        "The US National Institute for Standards and Technology (NIST) is looking to modernize its National Vulnerability Database (NVD) to address challenges posed by AI and incorporate more automation and AI workflows. In a request for information (RFI) published on August 12 in the Federal Register, NIST encouraged stakeholder input on opportunities, challenges and priorities for modernizing the NVD in “an evolving cybersecurity landscape increasingly shaped by AI and machine-consumable security data.” The Institute is particularly interested in receiving “forward-looking perspectives, practical recommendations and innovative models” that will improve the NVD’s scalability, automation, interoperability, transparency and utility."
        https://www.infosecurity-magazine.com/news/nist-seeks-public-input-ai-nvd/
        https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of
      • AI-Related Software Vulnerabilities: 2025–2026
        "AI and machine learning (ML) software has generated a steady stream of Common Vulnerabilities and Exposures (CVEs) in deep-learning frameworks, model-serving stacks, large language model (LLM) application platforms, agent frameworks and enterprise AI assistants. This article examines that body of AI-related software as a whole and compares it to the rest of the vulnerability corpus across 2025 and the first months of 2026: how severe its vulnerabilities are, how likely they are to be exploited, which weaknesses dominate, and who builds the affected software."
        https://blog.barracuda.com/2026/08/12/ai-related-software-vulnerabilities--2025-2026

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 10d34e5e-5741-4d2a-95ec-fbf96bb5408d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 12 August 2026

      Healthcare Sector

      • Mira Hormone Monitor, Mira Android App
        "Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01
      • Pulsetto Vagus Nerve Stimulator
        "Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02

      Industrial Sector

      • Industrial Ransomware Analysis For Q2 2026
        "In the second quarter (Q2) of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on Data Leak Sites (DLS) identified 1,140 ransomware incidents affecting industrial organizations worldwide, a 12% increase over the 1,020 incidents recorded in Q1. Ransomware remained the most persistent and disruptive cyber threat to industrial organizations in Q2 2026, sustaining the elevated pace established throughout 2025 and continuing to impact operational environments via the loss of enterprise IT systems, Enterprise Resource Planning (ERP) platforms, and virtualization infrastructure, versus direct manipulation of control systems."
        https://www.dragos.com/blog/dragos-industrial-ransomware-analysis-q2-2026
        https://www.helpnetsecurity.com/2026/08/11/industrial-ransomware-attacks-q2-2026/

      Telecom Sector

      • An AI Tool Found 84 Flaws In 5G Network Software And 23 Of Them Still Have No Fix
        "Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers. The most serious one lets an attacker take over a subscriber’s data session, so the network delivers that subscriber’s traffic to
        https://www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/
        https://arxiv.org/pdf/2607.10315
      • Researchers Show How Malicious SIM Cards Can Hijack Smartphones, EV Chargers And Connected Devices
        "Subscriber Identity Modules (SIMs), the secure element used to connect devices to a mobile network, can pose severe security risks when compromised. A malicious SIM could allow attackers to gather information about a device, interfere with its connectivity, and serve as an entry point for further cyberattacks. Presenting their findings at the 2026 USENIX WOOT Conference on Offensive Technologies, in Baltimore, University of Birmingham researchers reveal a new attack surface exposed to malicious and compromised SIMs."
        https://www.birmingham.ac.uk/news/2026/researchers-show-how-malicious-sim-cards-can-hijack-smartphones-ev-chargers-and-connected-devices
        https://www.usenix.org/system/files/woot26-lisowski.pdf
        https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
        https://www.helpnetsecurity.com/2026/08/11/malicious-sim-cards-hijack-phones-ev-chargers/

      Vulnerabilities

      • Adobe Urges Immediate Patching Of Critical ColdFusion, Campaign Classic Flaws
        "Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce. With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS). These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10)."
        https://www.securityweek.com/adobe-urges-immediate-patching-of-critical-coldfusion-campaign-classic-flaws/
      • SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
        "Enterprise software maker SAP on Tuesday announced the release of 28 new security notes, two updates to previous notes, and a GitHub advisory. Four of the notes published on SAP’s August 2026 Security Patch Day resolve critical vulnerabilities, the most severe of which is CVE-2026-58231 (CVSS score of 10/10), an improper authorization issue in SAP Commerce Cloud (Data Hub Adapter). The bug could allow remote attackers to bypass authentication, likely leading to code execution and unauthorized access to internal components. Successful exploitation would impact the confidentiality, integrity, and availability of the application."
        https://www.securityweek.com/sap-patches-critical-code-injection-memory-corruption-vulnerabilities/
      • Cisco Warns Of ASA And FTD VPN Flaw Exploited To Crash Devices
        "Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. The flaw, tracked as CVE-2026-20349, has a severity score of 8.6 and impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software with certain remote access services enabled. In a security advisory published today, Cisco said the vulnerability is caused by insufficient error checking while processing HTTP requests."
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
      • Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, 3 Zero-Days
        "Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. Patch Tuesday addresses 42 "Critical" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege."
        https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/
        https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2026/
        https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
        https://www.darkreading.com/application-security/microsofts-patch-tuesday-deluge-continues
        https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/
      • ZOOMSDAY
        "A critical vulnerability in Zoom, a platform used by 70% of the Fortune 100, discovered by publicly available frontier models, allows an attacker participating in a meeting a zero-click remote code execution on all meeting participants across all native clients. This research emphasizes the risk of weaponized AI and how vulnerable we are as an industry."
        https://a.security/blog/asecurity-zoomsday
        https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html
        https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/
        https://securityaffairs.com/197042/hacking/zoom-patches-zoomsday-zero-click-flaw-enabling-remote-code-execution.html
      • CISA Adds Three Known Exploited Vulnerabilities To Catalog
        "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
        CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
        CVE-2026-72898 Metabase SQL Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
      • CISA: Microsoft SharePoint Flaw Now Exploited In Ransomware Attacks
        "CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers. It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.""
        https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/
        https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
      • Cursor Security Bug Allowed Repositories To Execute Commands Before Trust Verification
        "A flaw in Cursor's command-line coding agent has been found to allow a cloned repository to run any command it chose on a developer's machine before they were asked whether they trusted it, and outside the sandbox even when the sandbox had been explicitly switched on. Manifold Security said it reported the issue to Cursor on July 20 and published its findings on August 10. Cursor shipped a fix for the pre-trust behavior three days after the report, then closed the submission as informative, meaning no security impact, and published no advisory. Francisco Rosales, offensive security engineer at Manifold, found the issue in the agent's isolated worktree feature, which exists to keep an AI agent away from a developer's working tree."
        https://www.infosecurity-magazine.com/news/cursor-security-bug-command/
      • Malicious MCP Servers Can Split Instructions To Make AI Coding Agents Exfiltrate Secrets
        "A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let the agent stitch them together and send the data back. The attack targets coding tools that connect to outside servers over the Model Context Protocol (MCP), the open standard that lets AI assistants call external tools."
        https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html
        https://github.com/asset-group/ghostsplice

      Malware

      • Fake Popular Sites Offer a Free App, Instead Take Over PCs
        "A website built to look almost exactly like CNN’s homepage is telling visitors to download “the new CNN app.” But it’s not CNN’s app, and has nothing to do with the news company. The campaign doesn’t stop at CNN. It also uses fake Stremio and Avast installers hosted on similarly convincing lookalike sites, all targeting Windows users. The installers are part of the same campaign to trick people into installing legitimate remote-management software that’s already linked to the attacker’s account."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-popular-sites-offer-a-free-app-instead-take-over-pcs
      • DeadLock Ransomware: Breaking Down a Rust-Based Encryptor With Decentralized Recovery Infrastructure
        "Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process. This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims. Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems."
        https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/
        https://www.bleepingcomputer.com/news/security/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/
        https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html
      • Delta Probes Wi-Fi Deauth Attack On Flight Carrying DEF CON Attendees
        "Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. ​The company told BleepingComputer that the incident occurred yesterday on Flight 591 and did not affect the safety of the passengers or aircraft operating systems. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated,” a company spokesperson said."
        https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/
        https://cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/
      • State Sponsored Hackers Use Fake Job Offers To Deliver New Zero Day Exploit
        "It typically begins the same way it has for years, with an approach from a recruiter offering a role at a company the target would recognize, accompanied by a PDF describing the position in convincing detail. That approach remains one of the most effective entry points used by state sponsored threat actors today, and Check Point Research has spent recent months tracking a new wave of it. Operation Dream Job, the long running campaign attributed to the North Korea affiliated Lazarus group, has resurfaced with a previously undisclosed Windows vulnerability (CVE-2026-68820), a newly identified backdoor, and a command and control architecture built almost entirely on infrastructure the group does not own."
        https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/
        https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
      • Six Npm Packages Use Ethereum Transactions To Retrieve Malicious Payloads
        "On August 10, 2026, Sonatype Research Labs identified six npm packages containing the same malicious payload, including three compromised legitimate packages and three packages published with the malware already present. The payload uses Ethereum blockchain transactions to locate infrastructure hosting additional JavaScript malware. Sonatype researchers confirmed the six packages use the same Ethereum wallet address in recent activity attributed to the DPRK-linked Contagious Interview campaign. OpenSourceMalware dubbed the specific blockchain-based command-and-control technique "NullReceiver," while Contagious Interview refers to the broader campaign associated with the Lazarus APT group."
        https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads
        https://www.infosecurity-magazine.com/news/npm-packages-ethereum-wallet-c2/
      • Fake CCleaner Installs GhostDesk Chrome Spyware
        "A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. With more than 2 billion downloads worldwide, CCleaner is one of the best-known Windows utilities, making it an attractive target for cybercriminals looking to distribute malware. The attack starts with a website that is a convincing imitation of the CCleaner download page. Once installed, the fake application launches an attack that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
      • Kimwolf v7: An Evolution Of The Kimwolf Botnet
        "We identified a new version (v7) of the Kimwolf Android/internet-of-things (IoT) botnet. This version upgrades its distributed denial-of-service (DDoS) attack capabilities and the resilience of its command-and-control (C2) infrastructure. Kimwolf primarily affects Android TV boxes and set-top boxes. Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints. This makes attack traffic more difficult to distinguish from legitimate browsing. The threat’s binary includes five hard-coded public Ethereum-based endpoints for resolving Ethereum Name Service (ENS) domains. ENS is a blockchain-based naming system used to obtain C2 addresses."
        https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
        https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html
        https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/
      • Project CAV3RN Continues: Google Apps Script As C2 Relay And DNS-Based C2 Channel Selection
        "Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence Reporting service, and the second was published on Securelist the following month, further documenting the framework’s evolving architecture and C2 capabilities. Continued tracking of this cluster in early August 2026 uncovered several previously undocumented components that expanded the framework’s communication and orchestration capabilities. The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. The same DNS infrastructure can validate and replace the relay deployment ID, allowing the operator to rotate the Google channel."
        https://securelist.com/project-cav3rn-continues/120991/
      • ExfilSquad Targets New Victims, Shares Data Via Torrents
        "ExfilSquad is an emerging cybercriminal hacking group identified in mid-2026 as responsible for high-profile data breaches. Notably, the group does not typically deploy ransomware or destructive malware; instead, they threaten to leak stolen data on a dedicated onion-based Data Leak Site (DLS) unless a ransom is paid. ExfilSquad announced new victims this week and set a firm deadline - August 5, 2026 - to complete all required negotiations. Otherwise, the stolen data will be released. This time, the list of victims includes 13 organizations from the U.S., the UK, and Sweden. Notably, in July, the group was also targeting a major financial institution in Nigeria."
        https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents
        https://securityaffairs.com/197025/security/exfilsquad-targets-new-victims-shares-data-via-torrents.html
      • AI Sidebar Extension Monetizes Its Own Updates
        "The Chrome extension “AI Sidebar with DeepSeek AI” that Google removed from the Chrome Web Store in January 2026 for stealing AI conversation content resumed shipping code to enterprise endpoints in July 2026. The extension released a benign update removing the data theft code and acknowledged its wrongdoing. After 2 weeks it pulled the rug again with a new update. Netskope Threat Labs analyzed the new build. While it no longer contains the conversation-exfiltration code, it now contains a monetization payload that opens an affiliate link in a foreground browser tab every single time the extension updates and uninstalls. Additionally, it suppresses the redirection of DeepSeek users to ChatGPT."
        https://www.netskope.com/blog/ai-sidebar-extension-monetizes-its-own-updates
        https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/
      • Phantom Project: A Cybercrime Toolkit Bundle
        "Phantom Project is a commercial cybercrime toolkit that bundles a stealer, a crypter and a remote access tool (RAT). It follows the standard Malware-as-a-Service (MaaS) model with tiered subscriptions for basic and advanced access. Researchers have observed the toolkit in Russian- and English-language phishing campaigns targeting users in more than 100 countries. Phantom Project activity was first observed in June 2025, though researchers found its distribution site had been registered in February of that year. Phantom Project activity accelerated through the second half of 2025, with multiple independent research teams documenting separate global campaigns within the same several-month window."
        https://blog.barracuda.com/2026/08/10/phantom-project--a-cybercrime-toolkit-bundle-
      • Researchers Built a Fake Crypto Startup And Hired Three Suspected North Korean IT Workers
        "Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account. The researchers said the image metadata showed it had been processed with Google Gemini. They also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit."
        https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
      • Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover On Windows 11
        "Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that redirection is not allowed by default. Security researchers Alejandro Hernando and Borja Martinez described the technique in "Plug And Pwn: Weaponizing Windows PnP Auto-Install," research prepared for DEF CON 34."
        https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html
        https://plugandpwn.com/
      • The Multi-Layered Defenses That Harden Chrome Against Abusive Notifications
        "Push notifications are a longstanding part of the open web, allowing developers to engage with users in real-time. However, bad actors have increasingly abused this system, bombarding people with deceptive and unwanted notifications. To combat this, Chrome Security has been on a multi-year journey, in collaboration with Firebase Cloud Messaging (FCM) and Safe Browsing, to significantly reduce notification abuse and improve the security and quality of the web ecosystem for everyone. After achieving a significant reduction in unwanted notification volume, reducing notifications on Android by over 7 billion a day in Q1 alone, today we’re pulling back the curtain on the multi-layered toolkit that secured this critical feature for billions of users."
        https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/
        https://www.bleepingcomputer.com/news/security/google-says-chrome-cuts-7-billion-unwanted-android-notifications-a-day-to-fight-abuse/

      Breaches/Hacks/Leaks

      • Mozilla Issues New Firefox GPG Key Following Exposure
        "Mozilla announced on Monday that it has issued a new GPG signing subkey used for some Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a GitHub repository. In general, if a GPG private signing key used for software releases is exposed, an attacker who obtains it could create valid signatures on malicious files. This creates a supply chain attack risk: the attacker could distribute modified or malicious versions of the software that appear authentic. Successful exploitation would still require a way to deliver the signed files to users, for instance via a compromised mirror, an alternate download path, or social engineering."
        https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/
        https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
        https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/
      • Wesco Confirms Security Incident After ExfilSquad Claims Data Theft
        "Global supply chain and distribution giant Wesco has confirmed in a statement to BleepingComputer that it is investigating a cybersecurity incident. The company's statement comes after data extortion group ExfilSquad claimed to have stolen sensitive information from Wesco and leaked it on their data leak site. Jennifer Sniderman, Vice President of Corporate Communications at Wesco, said that the incident involves the company's cloud CRM environment."
        https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/
      • Ransomware Group Hijacks Hospital System’s Facebook Page Amid Ongoing Cyberattack Fallout
        "Two weeks after a cyberattack knocked out its IT systems, the nonprofit medical system AnMed is still facing closures and the apparent hack of its Facebook page, which on Tuesday began showing ransom demands from the purported hackers. The social media page for the medical chain, which has four hospitals and other clinics in Georgia and South Carolina, was removed from Facebook shortly after a series of messages claiming to be from “The Gentlemen” ransomware group appeared."
        https://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response
      • Local Governments In Four States Dealing With Cyberattacks That Have Shut Down Services
        "The 911 system of a city in California was taken down by hackers during a cyberattack on Friday — one of several cyber incidents nationwide impacting government services. Suisun City, a town of 30,000 people in the Bay Area about 30 miles from Napa Valley, said on Friday that malicious software infected and compromised the city’s IT systems. The attack “hit critical public safety operations, including 911 routing, police and fire dispatch, records and City services,” according to a government notice. The city shut down the entire IT network and contacted federal and state officials for assistance. Emergency services are still available and public safety offices are routing calls through the county’s dispatch center."
        https://therecord.media/cyberattacks-ransomware-local-governments
        https://www.infosecurity-magazine.com/news/suisan-cyber-incident-government/

      General News

      • July 2026 Dark Web Breach Incident Trend Report
        "The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could not be definitively determined whether an actual breach had occurred."
        https://asec.ahnlab.com/en/94912/
      • July 2026 Dark Web Threat Actor Trend Report
        "The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified."
        https://asec.ahnlab.com/en/94917/
      • July 2026 Dark Web Issue Trend Report
        "The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements."
        https://asec.ahnlab.com/en/94918/
      • Who Will Be The Stanislav Petrov In Your Organization?
        "The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear missiles towards the Soviet Union. The officer on duty, Stanislav Petrov, did something computers still struggle to do. He applied context, experience, and human judgement to determine the warning was probably false. Thankfully, he was right. Had an automated response been allowed to proceed without meaningful human intervention, the result could have been a full blown nuclear war."
        https://www.helpnetsecurity.com/2026/08/11/governing-autonomous-ai-risks/
      • Cyber Security In Manufacturing
        "Cyber attacks are no longer just an IT issue for manufacturers. They are disrupting production lines, increasing costs and putting customer deliveries at risk. Make UK’s latest report, Cyber Security in Manufacturing, reveals the scale of cyber risk facing UK manufacturers and sets out the practical steps businesses can take to strengthen resilience."
        https://www.makeuk.org/insights/reports/cyber-security-manufacturing
        https://www.infosecurity-magazine.com/news/half-uk-manufacturers-cyber/
      • Cloudflare DDoS Threat Report H1 2026: 1 Tbps Attacks Soar As DNS Floods And Geopolitical Tensions Drive a New Wave
        "Welcome to the 25th edition of Cloudflare's DDoS Threat Report. This is the first half-year edition in the series: rather than publishing separate reports for the first and second quarters of 2026, we have combined our coverage of Q1 and Q2 into a single volume covering January through June 2026. The analysis is produced by Cloudforce One, Cloudflare’s Threat Intelligence organization, providing a comprehensive analysis of the evolving threat landscape of Distributed Denial of Service (DDoS) attacks based on data from the Cloudflare network."
        https://blog.cloudflare.com/ddos-threat-report-2026-h1/
        https://www.bleepingcomputer.com/news/security/ddos-attacks-over-1-tbps-surged-fivefold-in-the-second-quarter/
      • The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
        "AI governance, once the purview of the legal department, is now knocking on the CEO’s door. But many C-Suite executives are still treating it as something to delay addressing until after AI regulations are set in stone. This can be a shortsighted strategy. Consider that 46% of organizations say AI governance and compliance issues are the reason why their AI underperforms, according to the GrantThornton, 2026 AI Impact Survey Report (PDF). These figures lend credence to why leadership should not wait for AI regulations to settle but should apply governance proactively."
        https://www.securityweek.com/the-ai-governance-gap-is-a-leadership-problem-waiting-wont-close-it/
        https://www.grantthornton.com/content/dam/grantthornton/website/assets/content-page-files/advisory/ai-lp/infographic/ai-impact-survey-2026/pdf/grant-thornton-2026-ai-impact-survey.pdf
      • Hacker Conversations: Marcus Hutchins And The Journey From The Gray Zone To Redemption
        "Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. Born in Ascot, England, he was working as a cyber threat analyst for an LA-based cybersecurity company in 2017 (aged 22), when he became the world’s hero for finding a kill switch for the particularly virulent and destructive cryptoworm (ransomware spread by a worm) known as WannaCry. The ransomware decryption didn’t work, so there was no way to decrypt files once encrypted (it was effectively a wiper). But the worm worked very well, and more than 200,000 computers were affected in around 150 countries in just a few days."
        https://www.securityweek.com/hacker-conversations-marcus-hutchins/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) a01c4cb2-bba2-4e66-9941-fbc2f5393649-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 11 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
      • CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
      • CVE-2026-72898 Metabase SQL Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d613dd33-2931-4f8f-811d-ff9379a3b91f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ เมื่อวันที่ 11 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSMA-26-223-01 Mira Hormone Monitor, Mira Android App
      • ICSMA-26-223-02 Pulsetto Vagus Nerve Stimulator
      • ICSA-26-204-01 Johnson Controls C-CURE 9000 and Victor application server (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0c4215ba-6ab0-47a3-b65e-31db452f2781-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เตือนช่องโหว่ใน Progress Kemp LoadMaster ถูกใช้โจมตีจริง

      CISA เตือนช่องโหว่ใน Progress Kemp LoadMaster ถูกใช้โจมตีจริ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e2cf1732-d364-4a0f-97e0-818c71720b56-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • IEH แจ้งเหตุ Phishing กระทบ Microsoft 365 Mailbox อาจเปิดเผยข้อมูลทางทหารที่อยู่ภายใต้การควบคุมการส่งออก

      IEH แจ้งเหตุ Phishing กระทบ Microsoft 365 Mailbox อาจเปิดเผยข้อม.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 878ad2b4-7abc-483a-bd4e-d99f9d50cfae-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT