NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,634
    • กระทู้ 2,635
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • Cyber Threat Intelligence 02 October 2026

      Industrial Sector

      • Armatura LLC Armatura One
        "Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
      • Monta Monta.app
        "Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02
      • CISA Malcolm
        "The following versions of CISA Malcolm are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
      • ABB Protection And Control IED Manager PCM600
        "Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03
      • Johnson Controls EasyIO Neo Series EC And CW Controllers
        "Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04
      • Johnson Controls EasyIO Neo Series EC And CW Controllers
        "Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05
      • Meari IoT Cloud Platform OpenAPI Service
        "Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06

      Vulnerabilities

      • Fortinet Warns Of Critical FortiMail Flaw Exploited In Zero-Day Attacks
        "Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface. "An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory published Thursday."
        https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
        https://fortiguard.fortinet.com/psirt/FG-IR-26-175
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
      • Apple CoreGraphics PoC Emerges As WhatsApp PDF Checks Hint At Possible Delivery Path
        "Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate. Apple patched the flaw on September 28, crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.""
        https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html
        https://securityaffairs.com/200175/hacking/public-poc-released-for-apple-coregraphics-zero-day-cve-2026-86950.html

      Malware

      • AI Agents Targeted U.S. And Canadian Government Websites
        "Following up on our previous blog post, we discovered several additional incidents where rogue AI agents appear to have used aggressive techniques to access publicly available data on government websites. This includes two rudimentary and failed hacking attempts, one against the U.S. Department of Education’s Civil Rights Data Collection, and one against Library and Archives Canada, a Canadian federal agency. These failed attempts connect to additional rogue activity where agents used an array of aggressive tactics short of hacking to probe U.S. government websites, often using sites in unintended ways and sometimes violating explicit usage policies. This activity targeted websites across the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York."
        https://transluce.org/us-canada-gov
        https://www.bleepingcomputer.com/news/security/autonomous-ai-agents-tried-to-hack-us-canadian-government-websites/
      • Hallucinating Credibility: China-Aligned TA419 Impersonates Its Way Into US AI Policy Circles
        "In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an “AI Policy Advisory Committee”, to build rapport and solicit a response from the target. Once the target replied, TA419 followed up with a multi-stage URL redirection chain that led to an Adversary-in-the-Middle (AitM) credential phish that employed a customized version of the open-source Browser-in-the-Browser (BitB) phishing tool Frameless BitB."
        https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
        https://therecord.media/china-linked-phishing-scheme-backdoor-taiwan
        https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/
        https://www.infosecurity-magazine.com/news/ta419-impersonates-ai-experts-us/
      • Warlock Ransomware Attackers Hit Water And Telecom Operators
        "The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university."
        https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure
        https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese
      • Milk Dragon: Huge Discounts On Social Media? Think Twice Before You Buy
        "Phishing doesn’t always arrive in your inbox. In previous Group-IB blogs (GTFire Phishing Scheme and Phoenix Rising), we covered attacks that start with a suspicious email or text message. But some lures are designed to find you where your guard is at its lowest: your social media feed. Picture this. You’re doomscrolling late at night when an advertisement catches your eye. A brand you know and trust, selling products you actually want, at a discount that seems too good to pass up. No urgent warnings, no “act now or else,” no red flags screaming for attention. Just a deal that seems to pop up organically. That’s exactly what makes it dangerous: these attacks strike when your brain is on autopilot."
        https://www.group-ib.com/blog/milk-dragon-nailong-phishing-kit/
      • CloudSyncD: a Two-Stage MacOS Backdoor That Hides a Phished Password In Zero-Width Unicode
        "While performing routine monitoring of executables in VirusTotal, Jamf Threat Labs identified a macOS dropper buried within a disguised Zoom client. We are tracking this malware under the name CloudSyncD, after the daemon name its second stage runs under. We first encountered CloudSyncD on September 15, 2026, in a build that was plainly still under development. After two days of monitoring, we identified samples of the same family configured against live infrastructure across more than one command-and-control domain, indicating the operators have moved from testing toward deployment."
        https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer/
        https://www.infosecurity-magazine.com/news/cloudsyncd-macos-backdoor-fake/
      • MI5 Warns Over 100 Academics Helped China's Espionage Plans
        "The UK’s domestic security agency has warned that over 100 academics have helped Beijing’s spies to improve their espionage capabilities. MI5 issued the rare espionage alert on September 30, calling out the China General Technology Research Institute (CGTRI), or China Academy of General Technology (CAGT), for its connection to China's Ministry of State Security (MSS). Unusually for a security agency, the MSS handles both domestic/counterintelligence and foreign intelligence. It is thought to employ hundreds of thousands of workers, including many hackers that have been responsible for some of China’s most audacious campaigns, via ‘groups’ such as Silk Typhoon and Salt Typhoon."
        https://www.infosecurity-magazine.com/news/mi5-alerts-academics-chinese/
      • Fake xStocks, Pendle, And Other Sites Bait Crypto Users With Rewards Votes
        "We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out. However, the vote is fake and clicking the Vote now button opens a wallet connection prompt. It’s the first step toward requests that could trick visitors into authorizing access to their tokens."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/fake-xstocks-pendle-and-other-sites-bait-crypto-users-with-rewards-votes
      • SC WordPress Malware: A Self-Healing Mesh Of Loaders, Drop-Ins, And a Blockchain-Controlled Backdoor
        "During recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this article, we’ll refer to this family of malware as SC, named after the “SC_” markers found in the injected content. What makes SC worth documenting is how it survives. The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others. Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Clean every file on disk, and the next page load restores the whole set from the database or from a shared-memory segment. The result is a circular system with no single point you can remove to stop it."
        https://blog.sucuri.net/2026/09/sc-wordpress-malware-a-self-healing-mesh-of-loaders-drop-ins-and-a-blockchain-controlled-backdoor.html
        https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html
      • Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts And Hunt Indicators
        "CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Citrix and security researchers have already documented the vulnerability and its underlying exploitation mechanism. This analysis focuses instead on exploitation activity identified by LevelBlue's Threat Hunt Operations & Research (THOR) team while hunting across multiple customer environments."
        https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
        https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
      • Rogue Agents Investigation: Initial Findings
        "Asymmetric Security investigated suspicious AI agent activity on the public internet from March 6, 2026 to September 20, 2026. Below we list organizations whose data was accessed by these agents. In the vast majority of cases, all data retrieved was and is public. We also list tools the agents used to access the internet, in a capacity which we suspect was outside their remit. A more detailed writeup is now available."
        https://www.asymmetricsecurity.com/newsroom/rogue-agents-investigation-initial-findings/
        https://www.asymmetricsecurity.com/newsroom/rogue-agents-investigation/
        https://therecord.media/openai-software-attempted-to-secretly-scrape-data-from-dozens-of-websites
      • TIKTOUK: Tracing a WordPress Credential Collection Toolkit
        "TIKTOUK brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning. Its two Python components and Go-based Linux crawler turn website responses into structured results for a central hub: an HTTP service that distributes target tasks and receives collected data and status reports. The key security issue is the combination of exposed configuration material and encrypted plugin settings: the collection component used the corresponding keys to recover plaintext email credentials."
        https://www.levelblue.com/blogs/spiderlabs-blog/tiktouk-tracing-a-wordpress-credential-collection-toolkit

      Breaches/Hacks/Leaks

      • Metamask Discloses Security Incident Affecting Its Infrastructure
        "On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. The company is working to address the issue internally, with help from external partners and security advisors, and says there is "no immediate threat to MetaMask wallets." "As a precautionary measure, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients and partners," MetaMask noted. "As a reminder, our staking operations are non-custodial in nature and we do not manage withdrawal keys for stake on behalf of our clients.""
        https://www.bleepingcomputer.com/news/security/metamask-discloses-security-incident-affecting-its-infrastructure/
        https://thehackernews.com/2026/10/metamask-security-incident-prompts-exit.html
      • Cyberattack On Major Polish Invoicing Platform Exposes Customer Data
        "One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners. Fakturownia said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to servers. The company, whose service is used by more than 600,000 businesses, is still trying to determine how many customers were affected."
        https://therecord.media/poland-cyberattack-invoice-software

      General News

      • Teenager Suspected Of Leading KillSec Ransomware Group As Law Enforcement Seizes Servers And Leak Site
        "On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds."
        https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site
        https://www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/
        https://www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-mastermind-16-year-old
        https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html
        https://therecord.media/killsec-ransomware-raas-arrests-europe
        https://www.bankinfosecurity.com/spain-arrests-teen-suspected-running-killsec-ransomware-a-33002
        https://cyberscoop.com/killsec-ransomware-group-arrests-operation-killswitch/
        https://www.securityweek.com/police-shut-down-killsec-ransomware-identify-alleged-teen-leader/
        https://securityaffairs.com/200200/cyber-crime/operation-killswitch-police-dismantle-killsec-ransomware-group.html
        https://www.helpnetsecurity.com/2026/10/01/killsec-ransomware-16-year-old-main-operator-arrested/
      • The Fine Art Of Frustrating The Adversary
        "Years ago, Cisco Talos blocked an adversary’s command-and-control (C2) traffic. The adversary responded by tweeting, “Write a rule for your a**.” A fine endorsement of our work, if I’ve ever heard one. Talos loves to see an adversary forced to change course. And if every alternative for them is slower, less stealthy, less reliable and more expensive? Chef’s kiss. Adversaries rely on certain advantages. They look for environments where tools and infrastructure allow them to blend in with normal activity. They also look for employees who can be pressured into acting before they have time to think."
        https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/
      • Many Expect AI In The SOC To Make Entry Jobs Harder To Get
        "A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase the same familiar malware pattern and write up the same case note at the end of the shift. Eventually you know what normal looks like, which is how you notice when something isn’t. AI tools handle a lot of that repetitive work, and the people doing the job are glad to see it go. Nearly nine in ten respondents in a Swimlane survey of 500 security operations staff, all at organizations already using AI, say it has made their work more satisfying. The catch is who is saying it. About a quarter of respondents say AI has held back their ability to build security skills. Those analysts are just as happy with their jobs as the ones who say AI helped them learn: 91% versus 92%."
        https://www.helpnetsecurity.com/2026/10/01/ai-soc-entry-jobs/
      • Employment Scam Victims Tripled At Financial Firms In 21 Countries
        "Reported victims of employment scams more than tripled over the past 12 months at more than 370 banks and other financial institutions in 21 countries. The 258% rise outran every other scam type, while total reported scams across the same institutions grew 35%. Researchers at BioCatch, a fraud-detection vendor, compiled the figures from reports filed by the institutions that use its software. The numbers matter for anyone running fraud controls because of where the scams happen. Nine of every 10 scam sessions now start on a mobile device. Traditional unauthorized fraud, where a criminal works the account without the owner’s help, comes from mobile in 75% of cases."
        https://www.helpnetsecurity.com/2026/10/01/employment-scam-victims-research/
      • AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
        "Threats targeting AI systems is the area that cybersecurity leaders currently feel last able to address, with skills, accountability and data protection gaps also looming large, according to PwC. The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1. Over half (52%) said adversarial AI attacks represent the biggest cyber preparedness gap. The challenge of responding to these risks is compounded by governance issues."
        https://www.infosecurity-magazine.com/news/mitigating-adversarial-ai-top/
        https://www.securityweek.com/enterprises-struggle-to-prepare-for-ai-and-quantum-threats-pwc-says/
      • Shadow AI Explained: The Work Shortcut That Could Leak Your Company’s Secrets
        "Using an AI chatbot, assistant, or browser to speed up your work is tempting, but doing it without your employer’s knowledge can put sensitive data at risk. You’re swamped, so you paste a long email thread into a free chatbot and ask for a summary. It works, it saves an hour, and nobody notices. But the thread may contain customer details or confidential plans you’ve just shared with an outside service. If your employer hasn’t approved that tool or how you’re using it, that’s shadow AI."
        https://www.malwarebytes.com/blog/ai/2026/10/shadow-ai-explained-the-work-shortcut-that-could-leak-your-companys-secrets
      • Hacker Conversations: Rob Juncker, a Knock At The Door And a Moral Compass
        "Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. “And I think every security leader should be able to answer ‘yes’ to that question, for so many reasons.” He started early, when his parents brought home an Apple IIc. He was 10. They wanted to use it for word processing; but within two days of it arriving he had the lid off, trying to figure out how it worked. He had a driving curiosity to understand it. This curiosity, which he describes more as a thirst for knowledge, started before the arrival of the Apple – but with hands-on access, it rapidly focused on technology."
        https://www.securityweek.com/hacker-conversations-rob-juncker-a-knock-at-the-door-and-a-moral-compass/
      • AI Has Changed Attack Speed, Not Security Fundamentals
        "People who know me well know that I am a very direct person and as such, I don’t enjoy overcomplicating terms used to describe straightforward things. In recent months, Frontier AI and other tools have allowed attackers and defenders alike to shorten the time required to identify vulnerabilities and develop exploits for those vulnerabilities. With this has come an awful lot of hype and buzz around the topic of “virtual patching.”"
        https://www.securityweek.com/ai-has-changed-attack-speed-not-security-fundamentals/
      • Treasury Blacklists Most-Wanted ATM Malware Developer And His Network
        "The US Treasury Department has sanctioned the alleged developer of malware used in ATM jackpotting attacks linked to Tren de Aragua (TdA), along with members of his network and two Mexico-based companies. Anibal Alexander Canelon Aguirre, known as ‘Prometheus,’ was added in March to the FBI’s Ten Most Wanted Fugitives list, becoming the first person on the list wanted for cybercrimes. Treasury describes him as “the alleged engineer of the malware used in ATM jackpotting attacks.” TdA typically uses the malware named Ploutus. Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States. The stolen cash is laundered, including through cryptocurrency, and moved to TdA members in various countries."
        https://www.securityweek.com/treasury-blacklists-most-wanted-atm-malware-developer-and-his-network/
      • Microsoft Says Threat Actors Are Ahead In The Early AI Race
        "Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. This comes from Microsoft's 2026 Digital Defense Report, which strongly focuses on how artificial intelligence is changing both offensive and defensive cybersecurity operations. Microsoft says AI is reducing the time, expertise, and cost required to discover and exploit weaknesses, while allowing attackers and defenders alike to operate with greater speed, scale, and autonomy."
        https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/
        https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/2026-Microsoft-Digital-Defense-Report.pdf
      • Federal PQC Orders Are Here: How To Prioritize Migration Before Q-Day
        "The United States is in a race to develop its quantum capabilities and to migrate critical systems to post-quantum cryptography before standard encryption practices become obsolete. That’s because AI is merging with quantum computing and rapidly accelerating the timeline to Q-day. Frontier models can allow technologists to identify more efficient ways to design, architect, and scale quantum computers. In fact, it is now estimated that previous timelines predicting Q-day’s arrival in 2031 are even further compressed."
        https://www.forescout.com/blog/federal-pqc-orders-are-here-how-to-prioritize-migration-before-q-day/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 42ee4b28-a045-4db4-bc3c-21ea7ed6e64b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 01 October 2026

      New Tooling

      • OWASP Noir: Open-Source Static Analysis Tool
        "OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from. Here’s where it gets useful. Shadow APIs, the endpoints that live in the code but never made it into any documentation, show up in Noir’s inventory right next to everything else, along with deprecated routes and undocumented handlers."
        https://www.helpnetsecurity.com/2026/09/30/owasp-noir-open-source-static-analysis-tool/
        https://github.com/owasp-noir/noir

      Vulnerabilities

      • Cisco Warns Of New SD-WAN Zero-Day Exploited In Attacks
        "Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard. "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned on Wednesday. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.""
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
        https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html
      • TeamViewer Urges Users To Patch Severe Flaws “as Soon As Possible”
        "Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. The highest-severity flaw is a remote session access control bypass (CVE-2026-92370) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems."
        https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/
      • WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
        "WatchGuard on Tuesday announced fixes for 15 vulnerabilities in Fireware OS, including a critical-severity remote code execution (RCE) bug. Tracked as CVE-2026-86131 (CVSS score of 9.2), the flaw is described as a code injection issue in how the operating system handles BOVPN over TLS client configurations. Successful exploitation could allow a remote attacker who controls the remote VPN server to execute commands with root privileges on the connecting Firebox appliance."
        https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/
        https://securityaffairs.com/200108/security/watchguard-fixes-critical-fireware-os-flaw-allowing-remote-code-execution.html
      • Chrome, Firefox Updates Patch Over 100 Vulnerabilities
        "Google and Mozilla on Tuesday announced fresh Chrome and Firefox updates that address over 100 vulnerabilities. The latest Chrome release was rolled out with fixes for 32 security defects, including a critical-severity buffer overflow issue in ANGLE tracked as CVE-2026-102331 and reported by an external researcher. Google addressed 25 high-severity security weaknesses, most of which are uninitialized resource and use-after-free vulnerabilities. It also resolved five high-severity type confusion flaws in the V8 JavaScript and WebAssembly engine."
        https://www.securityweek.com/chrome-firefox-updates-patch-over-100-vulnerabilities/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog
      • OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
        "A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way through being sent. The flaw, tracked as CVE-2026-84782, is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Fixed versions for the older 3.0, 1.1.1 and 1.0.2 branches go only to customers who pay for OpenSSL's premium support. OpenSSL 3.0 stopped getting public security fixes on September 7."
        https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html
        https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/

      Malware

      • Beware Of Malware Infection In Facebook Ads Offering Cryptocurrency Rewards
        "Just because it’s a familiar tactic doesn’t mean you can let your guard down. A similar attack method using cryptocurrency rewards as bait has recently been identified again. This time, a case was confirmed in which the Node.Js-based malware JSCEAL was distributed through Facebook ads impersonating a cryptocurrency exchange. The threat actors lured users to a site designed to resemble a real exchange, then sent different installation files depending on the operating system to execute the malware. Over the past two months, JSCEAL infections have been confirmed on approximately 1,500 PCs in Korea, with both Windows and macOS systems included as Attack Targets. Let’s take a look at how JSCEAL deceives users, from the moment they click an ad to the malware code execution."
        https://asec.ahnlab.com/en/95645/
      • Beware Of SMS Messages Claiming To Protect Your Pi Coin Account—phishing Sites Are Stealing Wallets
        "One day, out of the blue, I received a text message claiming to protect my cryptocurrency account. However, this message concealed a sinister intent: to steal the user’s wallet information. Recently, a smishing campaign was identified that impersonated Pi Coin account protection to lure users to phishing pages and steal their cryptocurrency wallet information. The threat actors present a screen designed to look like the actual Pi Network service and trick users into directly entering the confidential information needed to recover their wallets. Since this tactic has been consistently observed in various regions—including the US, Europe, India, and Vietnam—users in Korea cannot afford to let their guard down. Let’s take a closer look at the Pi Coin smishing scheme hidden behind the phrase “account protection.”"
        https://asec.ahnlab.com/en/95646/
      • SilverFox: Tracking The Distribution Of a Domestic Variant Of a Malicious Installation File Posing As KakaoTalk
        "The threat actor used SEO poisoning (a technique that exploits search results to redirect users to fake sites) to distribute a malicious installer disguised as a KakaoTalk installer. The appearance and packaging method of the installer changed continuously, and the threat actor sequentially used NSIS, Advanced Installer, and Inno Setup. It contained both legitimate installation files and malicious files. When a user ran the disguised installation file, shellcode (code loaded into memory and executed) was triggered, and the malicious payload was executed."
        https://asec.ahnlab.com/en/95642/
      • China-Nexus UAT-11587 Targets Government And Policy Organizations Across Asia With Antino Backdoor
        "Talos first identified UAT-11587’s campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026. The message recreated Gmail's attachment interface and directed the target into a cloud-hosted, multi-stage infection chain. Across this activity, our researchers assessed that the actor used several delivery methods, loader families, and post-compromise tools. One recurring final-stage payload was a custom Rust backdoor that Talos tracks as Antino. Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server."
        https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
      • Disrupting a Coordinated Model-Distillation Campaign
        "We recently identified and disrupted a coordinated campaign designed to extract protected reasoning from our models, with the earliest observed activity occurring in the first week of July. This activity is consistent with adversarial distillation: the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model. Protected reasoning is the model’s internal record for working through a task; extracting it can reveal information withheld from the final answer and help others reproduce the model’s capabilities."
        https://openai.com/index/disrupting-a-coordinated-model-distillation-campaign/
        https://cyberscoop.com/openai-moonshot-ai-model-distillation-attack/
      • 2CLoader: A New Malware Loader Delivering Vidar And Remus
        "In August 2026, Zscaler ThreatLabz identified a new loader, which we track as 2CLoader. ThreatLabz has observed the loader being used to distribute information stealers including Vidar and Remus in addition to XWorm RAT. 2CLoader has the ability to perform a wide range of anti-analysis and evasion techniques, including indirect system calls, anti-analysis checks, and installing Windows API hooks. In this blog post, ThreatLabz provides a technical deep dive into 2CLoader, covering its core features, evasion techniques, loader configuration, network communication, payload decryption, and execution options."
        https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus
      • Unauthenticated Command Injection On Internet-Facing Mail Servers: Tracking CVE-2026-73570
        "Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled, without requiring authentication or user interaction."
        https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
        https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html
      • Phishing Abuses RMM Tools For Persistent Access
        "In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software."
        https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/
        https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
      • US-Focused CSuite Phishing Steals Microsoft 365 Sessions And Deploys RMM Tools For Remote Access
        "ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems."
        https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html
      • Mobile Malware Warning From Ukrainian Researchers Includes iPhone Exploit Kit
        "Russian hackers are increasingly targeting the smartphones of Ukrainian military personnel and government officials for espionage and financially motivated attacks, according to a Ukrainian government report published this week. The hackers are going after both Android and iOS devices using malicious apps and sophisticated exploits, according to Ukraine’s State Service of Special Communications and Information Protection (SSSCIP)."
        https://therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android
      • MALFEX - A Malicious Npm Postinstall No Advisory Has Caught For Fourteen Months
        "Between August 2023 and September 2026, a single operator publishing under Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but unadvised, and four are benign tools the operator ships as cover. The three packages without advisories are the only active threats defenders can target today: function-flag (continuously malicious since 18 July 2025), cdn-img-fetch (still installable after npm seized its parent package, img-to-native), and function-color (a wrapper that pulls function-flag in as a dependency)."
        https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign
      • AI-Assisted Attacks Still Leave a Behavioral Trace
        "AI is increasingly being used to accelerate cyber-attacks, but attackers still leave detectable behavioral traces. This blog explores how Darktrace identified suspicious file delivery, command-and-control communications, beaconing activity, and other anomalies linked to AI-assisted campaigns through behavioral analysis."
        https://www.darktrace.com/blog/ai-assisted-attacks-still-leave-a-behavioral-trace
      • TerminalFix And Lorem Ipsum Loader Enable Covert Tunneling
        "In August 2026, Sophos analysts began investigating a series of Managed Detection and Response (MDR) cases that involved ClickFix-style lures and resulted in the deployment of a Python-based tunneling implant. Instead of a typical ClickFix lure that instructs victims to open the Run dialog box, these lures direct users to open a Windows Terminal window. This ClickFix variation is known as ‘TerminalFix’. TerminalFix is not linked to a specific threat group or a single campaign. In 2026, Sophos analysts have observed several malicious campaigns that incorporated these lures (see Figure 1) and resulted in multiple infection chains."
        https://www.sophos.com/en-us/blog/terminalfix-and-lorem-ipsum-loader-enable-covert-tunneling

      Breaches/Hacks/Leaks

      • DIVD Says Zammad Zero-Days Enabled AI-Driven Network Breach
        "The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. Previously, the nonprofit organization of volunteer security researchers said the attack was “loud and very, very messy,” driven by an AI agent that moved autonomously and decided its next steps without external intervention or direction. DIVD retrieved extensive details about the attack because the AI agent left behind clear explanations of its decisions, allowing the organization to reconstruct the incident."
        https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/
      • GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them.
        "We scanned 224 million public GitHub repositories, a snapshot of public code assembled to train AI models (The Stack v3), and found 543,699 unique credentials that still authenticated when we tested them in July 2026. The median one had been sitting in a public default branch for 784 days. The oldest was committed in 2009 and still works. Just under 200,000 of them were pushed after GitHub turned push protection on by default. The block does work where it applies, roughly halving the rate at which the credentials it recognises reach public code, but 51.8 percent of what is still live is a shape it does not recognise, and nothing about it helps the half million already there."
        https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them
        https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/
      • Bitget Hacked Via Zero-Day In Third-Party Security Products
        "Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. According to Bitget, two separate investigations by blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant said the threat actors accessed Bitget's wallet environment after compromising two security appliances with zero-day exploits."
        https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
      • South Africa Seeks Help After Cyberattack Targets Air Traffic Control
        "The South African state-owned company that provides air traffic control (ATC) and weather operations for approximately 10% of the world's airspace discovered ransomware-linked malware in an operational technology (OT) network, according to public documents released this month. The company, Air Traffic and Navigation Services (ATNS), believes that its technical team stopped the attack, but it issued a request for quotes (RFQ) seeking cyber-forensics firms to investigate the incident. A second attack, possibly an insider's theft of data, is also part of the investigation request."
        https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
      • PixelLeak: How AI Agents Exposed Developer Screenshots From Leading Tech Companies
        "Every day, developers hand the last mile of their work to an AI coding agent: summarize your changes, attach screenshots showing the changes, then submit them for review. It’s common sense that screenshots of internal, unreleased development work should not be posted where anyone can see them. But many AI agents have been doing just that. Glow Labs has identified over 13,000 internal images published openly on GitHub by developers at over 300 organizations, including one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider, and a Fortune 500 travel company. In this post we share how AI agents quietly leaked thousands of pre-release screenshots, why no security team caught it, and how to check if you're affected."
        https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies
        https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html
        https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/
      • OpenInfra Europe’s JFrog Artifactory Instance Breached, Packages Potentially Compromised
        "Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage. “Anyone who downloaded or installed artifacts from https://artifactory.nordix.org/ from August 28 and September 15, 2026 should immediately stop using them, remove them from their pipelines, and treat these packages as potentially compromised,” the message says."
        https://www.helpnetsecurity.com/2026/09/30/openinfra-jfrog-artifactory-instance-compromised/

      General News

      • August 2026 Threat Trend Report On APT Attacks (South Korea)
        "AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the types and statistics on domestic APT attacks identified during the month of August 2026."
        https://asec.ahnlab.com/en/95649/
      • Vulnerability Discovery And Exploitation Trends In The AI Era
        "Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered."
        https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era
        https://therecord.media/google-vulnerabilities-cyberattacks-ai
        https://www.bankinfosecurity.com/google-ai-finding-more-medium-risk-flaws-a-32979
        https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/
        https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/
      • EU Cyber Resilience Act Requirements For Containers And Kubernetes
        "Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets. Reporting obligations will begin on Sept. 11, 2026, with full enforcement kicking in on Dec. 11, 2027. The CRA brings new requirements for teams working with containers and Kubernetes regarding how cloud native applications are built, distributed, and maintained throughout their lifecycle."
        https://www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/
      • Most Open Critical And High Flaws Are Over 90 Days Old
        "Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems are months old. Of the critical and high-severity vulnerabilities open at the time of the snapshot, 97% in the Nordics had been exposed for more than 90 days, along with 92% in the UK and 86% in the US. The organizations already know about these flaws. Detectify says it confirms findings with payload-based testing, which sends a working attack request and checks the response, so the backlog consists of issues its scanner judged exploitable. In the best-performing market, fewer than one in seven open critical or high findings is less than three months old."
        https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/
      • Most Organizations Need Six Months Or Longer To Roll Out New Security Controls
        "Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team when something changes. Cisco says frontier AI models can find software vulnerabilities at a scale and speed no human team working alone can match. Fewer than one in ten respondents are confident they can stay ahead of the flood of new threats. Their answers put the slowdown inside the company: procurement delays, infrastructure decisions that IT owns, and priorities the C-suite sets elsewhere. Cisco says teams have the tools, and the drag comes from how the organization runs."
        https://www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/
      • Your Car’s App Could Be Telling Big Tech Who You Are And Where You Go
        "A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data. Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come with a privacy cost that drivers may struggle to see and are unable to refuse. We’ve covered cars and privacy a few times before, especially after Mozilla researchers described cars as a “privacy nightmare.”"
        https://www.malwarebytes.com/blog/news/2026/09/your-cars-app-could-be-telling-big-tech-who-you-are-and-where-you-go
        https://therecord.media/automakers-routinely-share-connected-car-data-third-parties
      • Ransomware Leverage Is Growing By The Terabyte: Takeaways From ThreatLabz 2026 Ransomware Report
        "Ransomware is no longer defined only by how many organizations get hit. The most important shifts are happening beneath the headline victim counts; in how attackers gain access, who they target first, and how much data they steal once they’re in. The newly released Zscaler ThreatLabz 2026 Ransomware Report examines ransomware activity from April 2025 through March 2026, with a focus on groups and affiliates, victim targeting, attack techniques, data theft, and payment patterns."
        https://www.zscaler.com/blogs/security-research/ransomware-leverage-growing-terabyte-takeaways-threatlabz-2026-ransomware
      • EvilTokens Takedown Shows Why Cybercrime Platforms Are Getting Harder To Stop
        "Microsoft’s disruption of the EvilTokens phishing-as-a-service platform highlights a growing challenge for defenders: Cybercrime infrastructure may be getting easier to rebuild than it is to dismantle. AI-assisted development, inexpensive infrastructure, and increasingly decentralized services are enabling criminal groups to recover quickly when individual platforms are taken offline."
        https://blog.barracuda.com/2026/09/30/eviltokens-takedown-cybercrime-platforms-harder-to-stop
      • Know Your Enemy: Browser-Based Attack Techniques In 2026
        "Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026."
        https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html
      • More Than Half Of UK Businesses Lack Confidence In Basic Cyber Skills
        "More than half of UK businesses lack confidence in their ability to perform at least one basic cybersecurity task, according to the government's latest skills survey. The annual research found 57 percent of businesses reported a basic technical skills gap, up from 49 percent last year despite tighter national standards and repeated government warnings about cyber resilience."
        https://www.theregister.com/security/2026/09/30/more-than-half-of-uk-businesses-lack-confidence-in-basic-cyber-skills/5299991

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c8bc407b-2488-4787-9004-7305c576d79b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ SC บน WordPress ฝังตัวหลายตำแหน่งและกู้คืน Backdoor หลังถูกลบ

      พบมัลแวร์ SC บน WordPress ฝังตัวหลายตำแหน่งและกู้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5947d358-87db-4418-a7b8-7ca731b94b3e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • WatchGuard ออกแพตช์แก้ช่องโหว่ Critical ใน Fireware OS เสี่ยงถูกสั่งดำเนินการคำสั่งด้วยสิทธิ์ Root

      WatchGuard ออกแพตช์แก้ช่องโหว่ Critical ใน Fireware OS เสี่ยงถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 830a225e-91c0-4a41-943d-31d358dce779-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการใช้ช่องโหว่ Zimbra (CVE-2026-73570) เพื่อติดตั้ง Web Shell และขโมยข้อมูลสำคัญ

      พบการใช้ช่องโหว่ Zimbra (CVE-2026-73570) เพื่อติดตั้ง Web Shell.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5cac0302-7e71-4f28-a6c3-0cabc617d98f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน TeamViewer Full Client และ Host เสี่ยงถูกรันคำสั่งและยกระดับสิทธิ์

      ช่องโหว่ใน TeamViewer Full Client และ Host เสี่ยงถูกรันคำสั.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 47197471-7679-4a2b-9190-4d62859700b9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ANSSI เผยเหตุขโมยข้อมูลภาษี ใช้ Password เจ้าหน้าที่ที่ถูกขโมย เข้าถึงข้อมูลนาน 7 สัปดาห์โดยไม่ถูกตรวจพบ

      ANSSI เผยเหตุขโมยข้อมูลภาษี ใช้ Password เจ้าหน้าที.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f2cfffbc-dac2-44be-a1b4-2e89e31172b4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • นักวิจัยพบ AI ที่ใช้สรุปอีเมล ถูกหลอกให้บิดเบือนข้อมูลได้ด้วยการแทรกข้อความปลอม

      นักวิจัยพบ AI ที่ใช้สรุปอีเมล ถูกหลอกให้บิด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 631eb31b-81be-4f14-ab48-3a3b9cec77cf-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบช่องโหว่ CoreGraphics ในอุปกรณ์ Apple เสี่ยงถูกใช้รันคำสั่งบนอุปกรณ์

      พบช่องโหว่ CoreGraphics ในอุปกรณ์ Apple เสี่ยงถูกใช้ร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 598eb855-8bcc-4a57-8eef-c170cdf84673-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Infostealer มุ่งเป้าบัญชี AI องค์กร เสี่ยงเปิดเผย Session, API Key และข้อมูลสำคัญ

      Infostealer มุ่งเป้าบัญชี AI องค์กร เสี่ยงเปิดเผย Sessi.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3f2cb96a-1bc2-4a0d-ac00-f201ce6b3410-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 30 September 2026

      Industrial Sector

      • Toptech TMS7 And TopHAT
        "Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02
      • VIVOTEK Camera Firmware
        "Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03
      • Anjvision YSSD-RTMP-H5
        "Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05
      • MikroTik RouterOS
        "Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
      • Viidure Dashcam Android Application
        "Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07
      • Lantronix G520 Series Cellular Gateway
        "Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01
      • Baicells Nova 430H
        "Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04

      New Tooling

      • OperTraitors: How Kubernetes Operators Betray Your Security Posture
        "Kubernetes operators are coded to drastically reduce operational toil by acting as automated site reliability engineers. However, their reliance on highly privileged service accounts introduces a severe, often overlooked security weak spot. To quantify and combat threats aiming to take advantage of this weak spot, we have released OperTraitor, an open-source, large language model (LLM)-powered analysis engine. OperTraitor ingests raw role-based access control (RBAC) configurations directly from locally installed operators and the OperatorHub catalog. Upon doing so, it calculates the difference between an operator's documented functionality and its actual granted privileges."
        https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/
        https://github.com/paloaltonetworks/opertraitor

      Vulnerabilities

      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog
      • New Spectre v2 Attack Variant Leaks Linux Root Password Hash In Minutes
        "A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes. A BTR attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code. By manipulating this leftover information, an attacker can trick the processor into temporarily executing the wrong instructions and potentially expose sensitive data."
        https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/
        https://www.vusec.net/projects/btr
        https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html
        https://www.securityweek.com/new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks/
      • Kiteworks Patches Critical Flaw, Brings Customer Systems Online
        "American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform. Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users."
        https://www.bleepingcomputer.com/news/security/kiteworks-lifts-shutdown-warning-after-patching-critical-flaw/
        https://www.kiteworks.com/company/press-releases/kiteworks-restores-systems-credible-threat/
        https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html
        https://cyberscoop.com/kiteworks-lifts-shutdown-advisory-after-credible-threat-intelligence-from-federal-authorities/
        https://www.infosecurity-magazine.com/news/kiteworks-customers-restart/
      • Look, Don't Load: Model Inspection In Unsloth Studio Leads To Critical Arbitrary Code Execution
        "What is Unsloth. Unsloth is one of the most popular open-source libraries for fine-tuning and quantizing LLMs, and it makes work that used to require deep systems knowledge accessible to a very large community. Studio is its browser-based front end, currently in beta. Enterprise relevance. Unsloth is part of established AI development workflows: Databricks includes the library in its AI v5 environment. Its role also extends to model distribution. Hugging Face ranks Unsloth as the third-largest source of model derivatives on the Hub, behind Qwen and Google, and a Forbes analysis highlights the need for enterprises to track the third-party artifacts they consume. These facts establish Unsloth’s relevance to enterprise AI teams, though they do not measure adoption of the affected Studio interface."
        https://www.pillar.security/blog/look-dont-load-model-inspection-in-unsloth-studio-leads-to-critical-arbitrary-code-execution
        https://www.darkreading.com/application-security/unsloth-studio-flaw-model-inspection-code-execution
      • Package Name To Role Credentials In Code Interpreter: Two RCE CVEs In The AgentCore Python SDK
        "One package name was all it took: the BeyondTrust Phantom Labs team turned a routine pip install into remote code execution inside an Amazon Bedrock AgentCore Code Interpreter sandbox twice, and, where the customer had configured the interpreter with an execution role, into that role's AWS credentials. This blog breaks down both CVEs in the AgentCore Python SDK and the proof-of-concept exploits behind them."
        https://www.beyondtrust.com/blog/entry/amazon-bedrock-agentcore-python-sdk-rce-cves
        https://www.infosecurity-magazine.com/news/aws-agentcore-sdk-flaws-ai/
      • Cycode Uncovers Account Takeover In MCP Python SDK
        "A malicious MCP server tricked the SDK into sending login credentials to the attacker instead of the real login provider. The Model Context Protocol (MCP) is an open standard introduced by Anthropic and donated to the Linux Foundation’s Agentic AI Foundation (AAF), which maintains it."
        https://cycode.com/blog/mcp-python-sdk-oauth-account-takeover/
        https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
      • Self-Replicating Prompt Injections Exist
        "We show the existence of a new variety of prompt injection, which can self-propagate akin to a computer worm. No impact was observed outside of the simulated tool calls in training and evaluation; we are sharing this due to the novel nature of the prompt injection, not because of any incident."
        https://alignment.openai.com/misalignment-reports/self-replicating-prompt-injections-exist/
        https://www.theregister.com/security/2026/09/29/add-one-more-ai-worry-to-the-nightmare-scenario-self-replicating-prompt-injections/5299922

      Malware

      • Swarming Against Citrix 0-Day Exploitation
        "GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise also expands the GOG through Project Swarm, which enables the broader security community to join the effort. The activity discussed in this blog was derived from a Swarm participant sensor."
        https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation
        https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
        https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
        https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/
        https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
        https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
      • Beware Of Phishing Emails Disguised As Quote Requests
        "Recently, the AhnLab SEcurity intelligence Center (ASEC) confirmed that phishing emails disguised as requests for project quotes are being circulated. The email body is disguised as a request to submit a quote for discussing the project budget and prompts recipients to download an attached compressed file for verification."
        https://asec.ahnlab.com/en/95599/
      • Beware Of Phishing Emails That Disguise Themselves As Project Material Purchase Requests
        "Recently, the AhnLab SEcurity intelligence Center (ASEC) identified a case of phishing emails that disguise themselves as project material purchase request forms. These emails impersonate employees of a specific company in Korea and trick recipients into opening a malicious XLS file attached to the email, which is disguised as a project material purchase request form."
        https://asec.ahnlab.com/en/95598/
      • Attackers Abuse ChatGPT Custom GPTs To Deliver RAT Via ClickFix
        "Attackers are abusing ChatGPT Custom GPTs to impersonate legitimate product offerings, then directing victims to a malicious "backup" site through a trusted ChatGPT-hosted interface. Huntress researchers found two Custom GPTs linked to the same campaign that were being used in this manner. The campaign uses a ClickFix lure to trick victims into running PowerShell, which downloads a malicious MSI and begins a multi-stage, obfuscated infection chain. The payload establishes resilient access through dual persistence and DLL sideloading, using a Canon-signed executable (and, in a later wave, a Stardock-signed one) to load malicious code. Huntress investigated at least 40 related incidents, including two confirmed Custom GPT-driven infections."
        https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat
        https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/
        https://www.securityweek.com/hackers-use-chatgpt-custom-gpts-in-clickfix-attacks/
        https://www.helpnetsecurity.com/2026/09/29/malicious-chatgpt-custom-gpt-malware-via-clickfix/
      • Star Blizzard Refines Phishing And Malware Delivery With The RedFlick Technique
        "Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”. These changes represent a notable shift in the actor’s operational tradecraft and support ongoing cyberespionage activity targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations associated with international policy—particularly those with a nexus in supporting Ukraine."
        https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/
        https://cyberscoop.com/microsoft-star-blizzard-redflick-phishing-campaigns/
      • From BlackCat To Panda Workshop: Inside The Evolving C2 Panel Behind RATHat
        "RATHat is an Android banking trojan recently documented in public reporting, distinguished by an architecture in which the malicious application is only the entry point. Once granted the Accessibility Service, the application enables wireless debugging on its own, pairs with the device's ADB daemon to obtain a shell, and uses it to stage a native Go service and an FRP client that opens a reverse tunnel to the operator. The service runs outside the application's process and permission model, keeps its own channel to the C2, and survives the removal of the application until the next reboot. A shell that the malware grants itself, rather than a permission the user grants the application, is a model other families may adopt, and security controls should extend to this scope."
        https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
        https://www.infosecurity-magazine.com/news/rathat-c2-panel-malware-as-a/
      • Fake iPhone Duo Preorder Scam Triggers DarkSword Attack
        "Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it. Most of what we found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud. But one fake preorder page was different."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-iphone-duo-preorder-scam-triggers-darksword-attack
      • From EDU Account Takeover To Job Scam Abuse: West African Fraud Actors Target Universities
        "Proofpoint is tracking a cluster of threat activity specifically targeting U.S. universities. The fraud ecosystem observed in campaigns aligns with known advance fee fraud (AFF) tactics. The campaigns begin with credential harvesting attempts that lead to job scam monetization leveraging AFF. University students, staff, and alumni are a perennial target for many different types of cybercrime, including job scams, fake scholarships, and account takeover (ATO) activities. Threat actors find higher education email accounts valuable for a variety of reasons including: younger students may have less experience with email correspondence and are new to engaging with potential work or money-making opportunities; alumni may still have active email accounts, but may not use them frequently, providing an opportunity for threat actors to hijack their contact lists; and staff and faculty are constantly receiving communications from students, parents, community members, etc. from a variety of personal and university emails."
        https://www.proofpoint.com/us/blog/threat-insight/edu-account-takeover-job-scam-abuse-west-african-fraud-actors-target
      • PhantomSub: Malicious Npm Campaign Secretly Adds Users To WhatsApp Spam Channels
        "The OX Research team identified 101 npm packages as part of a malicious WhatsApp group subscriber campaign. The malicious packages abuse the “Baileys” WhatsApp open source project to add the victims to groups without their consent. 16 of those packages were removed from npm as of September 28, 2026. Earlier reports of Baileys WhatsApp campaign were made by SafeDep, OSV and Xygeni back in August and September 2026. Baileys is an open source project containing an unofficial implementation of the WhatsApp API used by developers to automate actions through their WhatsApp accounts – such as customer support bots, chat managers or data scraping."
        https://www.ox.security/blog/phantomsub-malicious-npm-campaign-secretly-adds-users-to-whatsapp-spam-channels/
        https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html
      • Operation Master: Deconstructing a Multi-Tiered Intrusion And Monetization Pipeline
        "SOCRadar Threat Research Unit (STRU) has uncovered an end-to-end cybercrime operation dubbed Operation Master, in which a threat actor compromised enterprise networks, stole customer and billing databases, offered portions of the data for sale on underground forums, and later repurposed those exact assets to power an automated, multi-tenant invoice fraud platform. Operating across multiple countries, the threat actor compromised critical network infrastructure, including VPN gateways via a GlobalProtect authentication bypass (CVE-2026-0257), while concurrently executing advanced web application exploits, deploying the AdaptixC2 framework, and leveraging an AI-assisted development workflow."
        https://socradar.io/blog/operation-master-intrusion-monetization-pipeline/

      Breaches/Hacks/Leaks

      • It Was a Matter Of When, Not If...
        "Security people always say it’s not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we’re the hackers that got hacked. We noticed suspicious activity, investigated, and came to the inevitable conclusion that damn, we got hacked. So what do hackers do when they get hacked? Handle it the way we think it should be handled. That is open, transparent and honest, even if it sucks. So far, we’ve been in full incident response mode, blocked access to our infrastructure and started a forensics investigation with the assistance of a third party incident response team."
        https://www.divd.nl/newsroom/articles/when-no-if/
        https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/
      • French Tax Data Theft Using Stolen Staff Passwords Went Undetected For Seven Weeks
        "An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak login protection, poorly separated networks and gaps in monitoring. The tax administration, known as the DGFIP, runs France's tax website, impots.gouv.fr. The data came from E-Contact, the tool taxpayers use to message the tax administration."
        https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html
      • Russian Pizza Chain With 1,500 Locations Confirms Cyberattack Following Hacker Claims
        "Hackers breached the systems of popular Russian fast-food chain Dodo Pizza and gained access to some customers’ personal information, the company said Monday. According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details. The company said it does not store customers’ payment information and that payment data was therefore not compromised. “The attackers’ access has been blocked, and an internal investigation is ongoing,” Dodo Pizza said, adding that it had notified Russian communications regulator Roskomnadzor about the incident."
        https://therecord.media/russian-pizza-chain-dodo-confirms-data-breach
      • Arizona Supreme Court Says Hackers Stole Residents’ Personal Data
        "The Arizona Supreme Court announced Friday that the state’s court system was attacked by hackers who stole the personal information of “many Arizonans.” Arizona Supreme Court Chief Justice Ann Scott Timmer said in a statement that the state court system was targeted by criminal hackers “or their bots.” “Court leaders believe the criminal hackers copied personally identifiable information about many Arizonans,” Timmer said. “The Supreme Court’s Administrative Office of the Courts is in the process of alerting as many people as possible whose information it believes the criminal hackers copied.”"
        https://therecord.media/arizona-supreme-court-says-hackers-stole-data
      • Pentagon Personnel Agency Data Breach Impacts 3 Million People
        "The US Defense Manpower Data Center (DMDC), which maintains personnel records for the Pentagon, has started notifying people that their personal information was exposed. According to the DMDC’s notice, unauthorized users had access to one of its file-sharing servers for roughly nine months. A copy of the notification letter, dated September 18 and shared online by a recipient, says the problem was discovered in mid-July."
        https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/
        https://securityaffairs.com/200017/uncategorized/three-million-affected-in-pentagon-personnel-agency-data-breach.html

      General News

      • Former US Air Force Members Sent To Prison Over BEC Attacks
        "Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. According to court documents, 25-year-old Chijioke Timothy Odimegwu and 26-year-old Harafat Mogaji carried out these attacks while stationed at Dover Air Force Base in Delaware."
        https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
        https://therecord.media/us-air-force-members-given-6-year-sentence-cyber
      • Vietnamese Man Charged In $16 Million 'pig Butchering' Crypto Scam
        "A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. 37-year-old Trung Nguyen Van entered the United States through the San Ysidro, California / Mexico pedestrian border entry point on September 22 and was arrested before boarding a flight to Taiwan out of Los Angeles International Airport on September 24. One of Van's victims transferred about $16 million in cryptocurrency between June and August 2024 in transfers directly traceable to Van's cryptocurrency wallet, believing they were investing in a crypto investment platform called "Triangle.""
        https://www.bleepingcomputer.com/news/security/vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam/
      • Pro-Russia Hacktivists Increase OT Intrusion Claims Across EU
        "Claims of cyberattacks against operational technology and industrial environments increased significantly in 2025 - particularly those involving pro-Russia hacktivist groups, the European Union Agency for Cybersecurity warned. ENISA released its annual Threat Landscape report last week, finding that ideology-driven malicious cyberattacks accounted for 57.3% of all incidents the agency recorded in 2025, followed by financially motivated activity at about 30%. In total, there were 4,709 hacktivist claims against European Union member states last year, 89.5% of which involved distributed denial-of-service attacks. The rest involved unauthorized access."
        https://www.bankinfosecurity.com/pro-russia-hacktivists-increase-ot-intrusion-claims-across-eu-a-32966
        https://www.enisa.europa.eu/sites/default/files/2026-09/ENISA Threat Landscape 2026_Final.pdf
      • OpenAI’s GPT-6 Astra Ran Supply Chain Attacks Despite Being Told Not To
        "OpenAI’s GPT-6 Astra carried out supply chain attacks on software outside the scope of a security test, according to the UK AI Security Institute (AISI). AISI tested the model before its public release. The tests ran inside a simulation, so no live systems were touched. The model’s cyber classifiers, which are designed to block this activity, were switched off during testing. “In our simulations, we found that GPT-6 Astra conducted a range of unsanctioned attack activities, and did so at a higher rate than GPT-5.6 Sol and GPT-5.5. Attack activities included GPT-6 Astra creating fake identities which it used to deceive developers, posting comments from fake accounts arguing against the results of accurate security reviews, and delivering malicious payloads to open-source codebases,” the UK government research organization wrote."
        https://www.helpnetsecurity.com/2026/09/29/openai-gpt-6-astra-supply-chain-attacks-test-simulations/
        https://www.aisi.gov.uk/blog/gpt-6-astra-performs-unsanctioned-supply-chain-attacks-in-simulations
        https://securityaffairs.com/199947/ai/gpt-6-astra-and-the-supply-chain-attack-it-wasnt-asked-to-launch.html
      • OpenAI Agents Go Rogue: When AI Agents Bypass Guardrails
        "Recently and rather quietly, there have been reports that describe an alarming case where thousands of AI agents used a dormant wiki as a coordination mechanism. On the surface, it’s a fascinating technical story. But for technology leaders, it serves as something more important: a case study or a cautionary tale of how autonomous systems behave when given marching orders, tools, and enough freedom to pursue and produce outcomes."
        https://blog.barracuda.com/2026/09/29/openai-agents-go-rogue-ai-agent-governance
      • Four Cyber Threats Harboring Big Plans For The Future
        "Not unlike the fictional Skynet sending increasingly sophisticated ‘Terminators’ as older versions of the monster failed to achieve their earthly missions, cyberattacks are growing more persistent and automated, further testing an organization’s security maturity. To stay in tune with future risks, it has become imperative to treat resilience as an operational objective in constant flux."
        Priority: 3 - Important
        Relevance: General
        https://www.securityweek.com/four-cyber-threats-harboring-big-plans-for-the-future/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 032a1bd9-803f-4861-9aca-1f06b4e89063-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 5 รายการลงในแคตตาล็อก

      เมื่อวันที่ 24-25 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 5 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
      • CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability
      • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability
      • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
      • CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ec918105-23fc-4085-ab86-750f02fa84ab-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ เมื่อวันที่ 24 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-267-01 Botslab G980H Dashcams
      • ICSA-26-267-02 Eufy Omni C20, Omni X10 Pro
      • ICSA-26-258-02 Wärtsilä FOS-Onboard (Update A)
      • ICSA-26-209-02 Siemens Mendix Runtime (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6bc07576-215d-45c1-a498-4cff5d651cc8-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 4 รายการลงในแคตตาล็อก

      เมื่อวันที่ 22 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 4 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
      • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
      • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
      • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fcf6c52f-7679-4063-8e28-e01df193dbc0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 22 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-265-01 lwIP TCP/IP Stack MQTT Client Application
      • ICSA-26-265-02 lwIP (Lightweight IP)
      • ICSA-26-265-03 Siemens Siveillance Control
      • ICSA-26-265-04 Siemens SIPLUS and SIMATIC Products
      • ICSA-26-265-05 Siemens Desigo CC family
      • ICSA-26-265-06 Siemens Industrial Edge Management
      • ICSA-26-265-07 Siemens SIMOVE Fleetmanager and SIPLANT
      • ICSA-26-265-08 Siemens WTV676 and WTV776
      • ICSA-26-265-09 OpenPLC Runtime v3

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d8295e0c-f186-4c5d-a589-bd1f6daea8e1-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 29 September 2026

      Financial Sector

      • Security Issues In The Korean & Global Financial Sector In August 2026
        "In Attack Stage 1, phishing was the highest at 2.1, Up from 1.8 The previous month. In Attack Stage 2, dropper/downloader was the highest at 1.1, Down from 3.2 The previous month. In Stage 3 of the attack, Infostealers were the most prevalent at 0.3, Down from 0.4 The previous month. WebShells, Backdoors, HackTools, Ransomware, and CoinMiners remained at low levels."
        https://asec.ahnlab.com/en/95589/

      Industrial Sector

      • One Packet Can Crash OT Servers In Industrial Sectors
        "A newly disclosed flaw in an open source database used in industrial and Internet of Things (IoT) environments could let unauthenticated attackers crash vulnerable servers with a single specially crafted network packet. The zero-day vulnerability, tracked as CVE-2026-42542 affects TDengine, a time-series database that organizations in sectors like manufacturing, energy, automotive, and IoT use to store and analyze large volumes of data collected over time. Examples of such data include readings from sensors and industrial equipment, as well as application- and infrastructure-related performance metrics."
        https://www.darkreading.com/ics-ot-security/one-packet-crash-servers-tdengine
      • Update
        CVE-2026-42542 affected TDengine v3.4.0.0 through v3.4.1.5 and was fixed in v3.4.1.6, released
        Official advisory: https://docs.tdengine.com/security-guide/security-advisories/
        Release notes: https://docs.tdengine.com/release-history/notes/3.4.1.6/

      New Tooling

      • Authorizer: Open-Source Authentication And Authorization For Your Apps
        "Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts in a database they choose. Its maintainers have built a permissions engine and an interface for AI agents into the same Go program that logs users in, so a chatbot can ask whether a user may see a document before it fetches that document. This affects any team that connects an AI assistant to company files. A vector search, which is the lookup that finds text similar to a question, returns close matches without checking who asked. Authorizer gives the search a list of documents the user is allowed to see, and everything else is dropped before it is scored."
        https://www.helpnetsecurity.com/2026/09/28/authorizer-open-source-authentication-server/
        https://github.com/authorizerdev/authorizer

      Vulnerabilities

      • How I Could've Accessed 17 Trillion Microsoft Records
        "An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets were reachable through a single internal analytics service, all because it never checked the signature on a login token. That flaw let me claim an administrator’s identity and submit unauthorized SQL queries without any real credentials. I used only table descriptions, metadata, and bounded sample rows to understand the potential scope."
        https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records
        https://www.helpnetsecurity.com/2026/09/28/microsoft-titan-jwt-signature-flaw/
      • “Drunk” AI Is Terrible At Keeping Secrets
        "AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW Sydney researchers Anudeex Shetty, Aditya Joshi and Salil Kanhere, published in their paper “In Vino Veritas and Vulnerabilities.” “The key research question from the natural language processing (NLP) side for me was, how do we get LLMs drunk?” said Aditya Joshi, a senior lecturer at the UNSW School of Computer Science and Engineering. “And the cyber security question was, how do we measure their vulnerabilities once they are drunk?”"
        https://www.helpnetsecurity.com/2026/09/28/drunk-ai-models-jailbreak-research/
      • Apple Patches CoreGraphics Flaw Possibly Exploited In Targeted Attacks
        "Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue."
        https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html

      Malware

      • Vulnerability Attack Case: Installation Of a Web Shell And Execution Of a Scanner By Exploiting a Telerik UI Vulnerability
        "The AhnLab SEcurity intelligence Center (ASEC) has identified two vulnerability attack cases that exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers. In the first incident, after exploiting the vulnerability, the attacker executed a reverse shell, attempted to perform privilege escalation, and installed a web shell; in the second incident, the attacker ran a scanner tool to search for additional Attack Targets."
        https://asec.ahnlab.com/en/95561/
      • Storm-3168: Agentic-Driven Cloud Attacks Using Compromised Service Principals
        "Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. Our investigation found an extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration."
        https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/
        https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
        https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/
        https://www.darkreading.com/cloud-security/jadepuffer-ai-actor-azure-tenant-destructive-cloud-attack
        https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html
      • Chrome Store Hosts 'Poper Blocker' Spyware Downloaded By Millions
        "Millions of people have downloaded infostealers disguised as legitimate ad-blocking browser extensions, in part because Google has provided them with seals of approval on the Chrome Web Store. That's the word from Bay Area Labs, which uncovered one such app, "Poper Blocker," lurking in the Chrome Web Store. Poper Blocker has every trapping of a legitimate, mainstream app: It sports a big, green "Featured" badge, and its developer has earned a trustworthy "Established Publisher" status with Google. It enjoys a 4.8 out of 5 star rating from more than 81,000 reviewers. It claims more than 2 million active users. In short, no user could spot anything untoward about this program were they to come across it while shopping for an ad blocker."
        https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions
      • NeedyMantis: Unpacking a Post-Compromise Malware Family Used In Targeted Operations
        "Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations."
        https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
        https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
      • RatHat Android Malware Console Uses Gemini To Identify Higher-Value Victims
        "RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps. Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups."
        https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html
      • The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, And AI Environments
        "Identity has long been the primary attack surface of the cloud. Infostealer malware, distributed through an industrialized cybercrime economy, is a leading initial access vector for compromising enterprise cloud, code, and AI environments. By targeting unsecured endpoints of developers through social engineering and supply chain attacks, threat actors steal credentials, API keys, and active session tokens, thereby bypassing the stronger defenses protecting most cloud environments from more direct attacks. Stolen credentials are widely recognized as one of the most common initial infection vectors - Microsoft, Recorded Future, and Verizon’s DBIR all point to infostealers as a cause of major concern. These attacks begin with a simple malware infection on a personal device, and end with attackers gaining privileged access to your AWS, Azure, or GCP estate, and more recently to the code platforms used by your organization, such as GitHub or GitLab."
        https://www.wiz.io/blog/infostealer-incursion-cloud-ai-credentials
      • A Fake Security Locker, Delivered By Google Ads
        "Netskope Threat Labs has been tracking a cloud-hosted tech-support-scam (TSS) kit that hijacks a victim’s browser with a fake security alert and pressures them into calling a bogus support line, where the goal is to either extract payment for fake “support,” gain remote access, or collect personal and financial details. Victims arrive by clicking a Google ad and land on a loading spinner webpage then into what looks like an ordinary online store, with nothing that reads as malicious."
        https://www.netskope.com/blog/a-fake-security-locker-delivered-by-google-ads

      Breaches/Hacks/Leaks

      • Japan's Keio Confirms Ransomware Attack Disrupted Business Systems
        "Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. Following a system failure in the early hours of Saturday, the company confirmed the attack and shut down its network to prevent additional damage. The company said it is investigating the extent of the impact and whether the attackers accessed any customer or business partner information."
        https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/
      • Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
        "Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. The company announced the incident on September 25, saying that a third party had accessed its systems at the beginning of the month. Times Car took action to block the unauthorized access on September 26. At the time, the company said it was investigating whether the attackers accessed members' personal information, but confirmed the data theft in an update earlier today."
        https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
      • Everything Everywhere: Systemic Data Exposure In Supabase Apps
        "Since 2025, the database service Supabase has been known to leak data through a variety of configuration issues. Despite improvements to Supabase product security, those issues continue to exist; multiplied by Supabase’s growth as a favorite tool for Claude Code, there are now thousands of Supabase instances exposing personal information and other data. In the largest study of its kind, UpGuard Research shows how Supabase misconfigurations expose personal data for people all over the world."
        https://www.upguard.com/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps
        https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/
      • FBI Job Portals Remain Offline After ShinyHunters Claims Breach Via PeopleSoft Zero-Day
        "The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable, following what appears to be successful compromises by the ShinyHunters cyber extortion group. Last week, the United States’ domestic intelligence and security service confirmed it was investigating ShinyHunters’ claim of having compromised personal information of FBI employees. ShinyHunters told The Register they leveraged a currently unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach the portals."
        https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/
        https://cyberscoop.com/fbi-data-breach-shinyhunters-agent-safety-risk/
        https://www.malwarebytes.com/blog/data-breaches/2026/09/fbi-agents-blood-tests-and-doctors-notes-surface-after-breach
      • Bitget Says Attacker Exploited Third-Party Security Product Flaw To Steal $388M
        "The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets were not affected."
        https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
        https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/
        https://www.infosecurity-magazine.com/news/bitget-restarts-withdrawals-387-5m/
      • Cyberattack On Polish Medical Software Provider Exposes Patient Data
        "Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months. Qbusoft, which develops the Medyc medical records and practice management platform, was breached after an attacker exploited an SQL injection vulnerability in August, according to a notification issued last week by one of the healthcare providers affected by the incident. SQL injection is a security flaw that allows hackers to trick a website into giving them access to information stored in its database."
        https://therecord.media/poland-cyberattack-medical-medyc
      • DC Health Agency Exposes 400,000 Beneficiary Records
        "The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach. According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026. The data breach was not the result of hacking. Instead, DHCF discovered in July that two reports on its website contained hidden personal information accessible to unauthorized individuals."
        https://www.securityweek.com/dc-health-agency-exposes-400000-beneficiary-records/
        https://securityaffairs.com/199926/data-breach/nearly-400000-medicaid-beneficiaries-caught-in-medicaid-and-dc-healthcare-alliance-data-exposure.html

      General News

      • August 2026 Threat Trend Report On Ransomware
        "This report summarizes statistics on new ransomware samples, affected systems, and statistics on targeted businesses collected during the month of August 2026, as well as major Korean & Global ransomware issues. Statistics on targeted businesses were compiled based on the time when publicly available information from ransomware groups’ DLS (Dedicated Leak Sites, i.E., Ransomware PR sites or PR pages) was collected via the ATIP (AhnLab TIP, Threat Intelligence Platform) infrastructure."
        https://asec.ahnlab.com/en/95567/
      • Dutch Police Arrest ‘Reformed’ Hacker In Shiny Hunters Investigation
        "Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p."
        https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
        https://databreaches.net/2026/09/28/still-on-probation-from-previous-arrest-for-hacking-and-extortion-dutch-national-is-arrested-again/
        https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/
      • AI Agents Are Privileged Users; Who Is Auditing Their Access?
        "Enterprises spend heavily protecting the human perimeter. Security teams deploy phishing-resistant multifactor authentication (MFA), enforce rigid conditional access policies, and scrutinize every login from an unexpected IP address. Yet while we closely monitor the human employee, engineering teams are quietly granting broad production access to autonomous AI agents, which often operate as non-human identities (NHIs) backed by service accounts, API tokens, or delegated cloud permissions."
        https://www.darkreading.com/vulnerabilities-threats/ai-agents-are-privileged-users-who-is-auditing-their-access
      • If You Do One Security Check This Quarter, Make It Agent Memory
        "In this interview with Help Net Security, Chris Latimer, CEO of Vectorize, talks about the security risks hiding in AI agent memory. He found coding agents storing API keys, credentials, and sensitive documents in plain text on developer machines and in cloud services. Latimer explains how attackers could plant poisoned memories through plugins, skills, and MCP integrations, often aimed at new coders who trust too easily. He covers why access control for agent memory lags behind other areas, what to track after an incident, and the one audit he thinks every CISO should run this quarter."
        https://www.helpnetsecurity.com/2026/09/28/chris-latimer-vectorize-agent-memory-security/
      • AI Tests The Limits Of Enterprise Security Governance
        "AI agents are forcing enterprises to rethink security governance, human accountability and oversight as deployments scale. AWS’s Reimagine 2026 argues that organizations need to build governance into their systems and keep humans accountable for outcomes. The findings come from confidential interviews of 45 to 60 minutes with 154 executives at 128 organizations in 23 industries, conducted over nine months. A number of the organizations interviewed still apply review processes designed for six-month IT programs to work that takes days. If a two-week experiment waits a month for approval, some teams stop asking for permission. Policy in that situation is “pushing it underground,” the authors write."
        https://www.helpnetsecurity.com/2026/09/28/ai-agent-security-governance-aws-report/
      • Quantum Random Numbers Can Pass The Tests And Still Leak Clues To Attackers
        "The European Telecommunications Standards Institute’s (ETSI) technical report, ETSI TR 104 171, offers guidance on building and evaluating quantum random number generators (QRNGs). It focuses on weaknesses in the devices and their supporting systems that could make the numbers they produce less secure. A QRNG measures a quantum process and turns the raw results into usable random numbers. Cryptographic systems rely on unpredictable numbers to generate keys and perform other security functions. If an attacker can predict those numbers, the protection those systems provide may be weakened."
        https://www.helpnetsecurity.com/2026/09/28/quantum-random-number-generator-qrng-guidance/
      • Deepfakes Are Becoming a Costly Reality For Businesses, Report Warns
        "Three quarters of cybersecurity leaders say their organization has faced a suspected deepfake incident during the last year and a quarter of those hit by one say it cost the business over $1m in total, a new report has warned. The 2026 Pindrop Deepfake Readiness Index, published on 28 September, warned there is a significant gap between the threat of deepfake attacks and enterprise readiness to defend against them. Deepfakes are AI generated audio and videos of people. The technology has become increasingly sophisticated, making it difficult for anyone watching or listening to the deepfake to tell that it isn’t footage of a real person."
        https://www.infosecurity-magazine.com/news/deepfakes-costly-reality-for/
      • MCP Is Creating Major Governance Gaps, Researchers Warn
        "Model Context Protocol (MCP) servers are creating a silent enterprise governance gap which threatens to undermine cybersecurity efforts as AI deployments proliferate, according to new research from Ox Security. MCP connects AI applications to external tools and data in a standardized manner, so that developers don’t have to write custom code each time they want to connect AI to an API or database."
        https://www.infosecurity-magazine.com/news/mcp-creating-major-governance-gaps/
      • AI Accounts Are Becoming The New Target For Infostealers
        "SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent rather than the result of historical cleanup. Together, these companies account for 5,434 stealer log records linked to 1,500 distinct corporate email addresses. The number that really stands out is the ChatGPT figure. A captured ChatGPT or OpenAI session appeared at 358 of the 482 companies, accounting for roughly 90% of all records in the study. Other platforms, including Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs, were far behind."
        https://securityaffairs.com/199933/ai/ai-accounts-are-becoming-the-new-target-for-infostealers.html
        https://socradar.io/resources/report/ai-identity-exposure-report-2026.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e6cb8319-d61a-4b1c-bbae-4272190ddf47-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบ x47.c บอตเน็ต Windows ใช้ Grok ช่วยคงอยู่ในระบบ พร้อมความสามารถ AI API Drain

      พบ x47.c บอตเน็ต Windows ใช้ Grok ช่วยคงอยู่ในระบบ พร้อ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c972b94c-f61a-4e91-91f1-816fcf59ced2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • OpenAI เผยเหตุ AI Agents อัปโหลดรูปภาพผู้ใช้ไปยังเว็บไซต์ภายนอกโดยไม่ได้ตั้งใจ

      OpenAI เผยเหตุ AI Agents อัปโหลดรูปภาพผู้ใช้ไปยังเว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c0e14281-2ecd-490e-bccd-c82ac481e268-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ Lunex อาศัยช่องโหว่ไดรเวอร์ AMD ข้ามผ่านระบบรักษาความปลอดภัยเพื่อขโมยข้อมูลผู้ใช้งาน

      พบมัลแวร์ Lunex อาศัยช่องโหว่ไดรเวอร์ AMD ข้ามผ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 76e79886-d0a3-48b9-8c14-eb1a5414c1c7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 28 September 2026

      Industrial Sector

      • Considerations For Critical Infrastructure Operators Working With Third-Party ICS Integrators
        "The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators. ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control."
        https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators
        https://www.bankinfosecurity.com/cisa-fbi-warn-ot-operators-about-third-party-hacking-a-32942

      Telecom Sector

      • Inside The Telecom Attack Surface: SS7, BGP Hijacking, And The Technical Reality Of Nation-State Intrusions
        "Nation-state operators rarely need a zero-day to get inside a carrier. Much of the telecom stack still runs protocols designed when every participant was a known, trusted operator. SS7 assumes that the node sending a request has a legitimate reason to send it. BGP assumes a network announcing a route actually owns it. Attackers who understand those assumptions can operate inside a carrier for years without triggering a single alert. For telecom CISOs and SOC teams, defending this environment starts with understanding how these attacks actually work."
        https://cyble.com/blog/ss7-bgp-nation-state-intrusions/

      Vulnerabilities

      • Citrix Confirms Two NetScaler RCE Zero-Days Exploited In Attacks
        "Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend. NetScaler appliances are particularly valuable targets because organizations commonly deploy them as Internet-facing edge devices that provide remote access and application delivery services for internal corporate networks."
        https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
        https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
        https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
        https://securityaffairs.com/199873/security/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability
        CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
        https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html
        https://securityaffairs.com/199777/hacking/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html
        https://www.securityweek.com/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog
        https://securityaffairs.com/199790/security/u-s-cisa-adds-wordpress-flaw-to-its-known-exploited-vulnerabilities-catalog.html
      • Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks
        "Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. According to German technology publication Heise, Kiteworks CISO Frank Balonis emailed customers warning that the company had received "credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend.""
        https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/
        https://therecord.media/kiteworks-urges-customers-to-stop-using-systems-incident
        https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html
      • Cross-Site Request Forgery In Elementor Plugin Affecting 2 Million+ Sites
        "This blog post is about a Cross-Site Request Forgery vulnerability in the Elementor Website Builder plugin. One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform. On a stock installation, an administrator clicking the link creates a second administrator account for the attacker. The link needs no JavaScript, no form, and no page under the attacker’s control. It works as a plain anchor in an email, a chat message, or a comment. Patchstack has issued mitigation rules to protect against exploitation of this vulnerability."
        https://patchstack.com/articles/cross-site-request-forgery-in-elementor-plugin-affecting-2-million-sites/
        https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/
        https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html
      • SalesBleed: Indirect Prompt Injection And 0-Click Data Exfiltration On Agentforce
        "We found a way to pull sensitive account data out of Salesforce Agentforce without ever logging in, or requiring the victim to click anything. The entry point was a public Web-to-Lead form, the exit was a DNS query. We call it SalesBleed. In between, sat a few guardrails and Salesforce's Trusted URLs mechanism, which is a redaction layer built to strip untrusted URLs out of agent responses before a user ever sees them. We were eventually able to fully bypass all these mechanisms and exfiltrate data."
        https://labs.zenity.io/post/salesbleed-0-click-data-exfiltration-on-agentforce
        https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/
        https://www.securityweek.com/salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration/
      • How Cloudflare Addressed a Cross-Tenant Data Exposure Vulnerability In Containers
        "On September 4, 2026, Oren Yomtov, a security researcher from Accomplish, responsibly reported a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes (which is built on Containers), through Cloudflare’s bug bounty program. Cloudflare has fully remediated the vulnerability, and we have no evidence that customer data has been compromised. This post was prepared in collaboration with Oren Yomtov and the Accomplish security research team, whose detailed report and controlled testing helped us validate the issue and respond quickly."
        https://blog.cloudflare.com/containers-cross-tenant-vulnerability/
        https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html
        https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/
      • File Notification Attacks
        "File-notification systems tell applications when files change, e.g., opened, closed, written, deleted. With only read permission on a file or directory, an attacker can watch these notifications and reconstruct user behavior. We find generic issues similar on each of Linux, Android, Windows, and macOS. However, there are three issues that are severe and unique to their platform: 1. On Linux, watching a readable directory reports every event on a file inside it, even one the attacker cannot read directly. The most severe case of this is with /dev/input, discussed in Inter-Keystroke Timing below. 2. On Android, FileObserver bypasses the FUSE layer's per-app storage view, letting an unprivileged app watch another app's private folder. We show this against WhatsApp, revealing exactly when photos, videos, and files arrive or get deleted, detailed in Revealing Private Communication below."
        https://inoti.fyi/
        https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability
        CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog

      Malware

      • The Brand Was Real. The Desktop App Wasn’t.
        "Someone is impersonating major HR and payroll platforms with “native desktop apps” that do not exist. The download is real and what it installs is real, but it is not what the victim is expecting. The file is a copy of ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) tool of the kind IT teams use to administer machines remotely, configured here for silent unattended access and pinned to the attacker’s server. The lure pages were generated with an AI app builder and hosted on Vercel, the payload was served from GitHub Releases, and a single operator ran at least three brand lookalikes at once."
        https://alluresecurity.com/blog/signal-noise-brand-was-real-app-wasnt
        https://www.helpnetsecurity.com/2026/09/25/fake-payroll-desktop-apps-screenconnect/
        https://www.theregister.com/security/2026/09/25/crooks-use-fake-desktop-apps-to-fool-hr-staff-into-giving-them-remote-access/5299226
      • AliExpress Phishing Campaign: What EfficientIP Research Labs Uncovered
        "EfficientIP Research Labs uncovered an AliExpress phishing campaign designed to lure people to a convincing fake shopping site. On June 9, researchers identified ten potential web addresses before they were registered and added them to DNS Threat Pulse. On July 2, the addresses became active, and their shared naming patterns and infrastructure linked them to the same campaign. The campaign directed visitors through a series of links to a fake AliExpress-themed site. It used familiar branding, a lookalike name and an “Add to Browser” prompt encouraging visitors to install a shopping-assistant extension. Several independent security services classified the destination as malicious or unsafe."
        https://efficientip.com/blog/aliexpress-phishing-campaign-dns/
        https://www.infosecurity-magazine.com/news/aliexpress-phishing-flagged-early/
      • Kothamine Malware Uses Tailscale’s Tailcat To Evade Network Detection
        "We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone. We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection
      • Threat Actors Use Google Ads To Target Ledger Users
        "In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake device-verification process prompted users to enter their secret recovery phrases, which attackers could use to access their wallets without the physical devices. In this blog post, ThreatLabz examines the campaign’s infrastructure and the steps used to trick users into submitting their recovery phrases."
        https://www.zscaler.com/blogs/security-research/threat-actors-use-google-ads-target-ledger-users
      • Re-Enabled GitHub Actions Expose Thousands Of Repositories To Mini Shai-Hulud
        "The GitHub Actions actions-cool/issues-helper and actions-cool/maintain-one-comment were compromised in the May 2026 Mini Shai-Hulud campaign. GitHub security team disabled both repositories on May 19, 2026, one day after the malicious content was introduced. Disabling the repositories stopped the attack: downstream workflows could no longer download either action, so they failed before any action code ran. On September 16, 2026, both repositories became accessible again. Their release tags were not cleaned up first. They still point to the malicious content introduced on May 18, so any workflow that references either action by a version tag resumed downloading and executing the payload on its next run."
        https://socket.dev/blog/mini-shai-hulud-actions
        https://thehackernews.com/2026/09/compromised-github-actions-came-back.html
        https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/
      • PamStealer Adapts Again: a Move To Swift With a Server-Side Decryption Chain
        "Following our July 2026 publication of PamStealer, Jamf Threat Labs has continued to monitor and identify additional variants. While our earliest publication documented a compiled JXA dropper distributed as a fake Maccy clipboard manager, the sample analyzed here uses the same compiled JXA outer format but shifts the lure and rebuilds the delivery chain entirely. What distinguishes this variant from its earlier ones is not what it collects but how it is delivered. Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped. Without the server's cooperation, the payload cannot be recovered statically. The second stage has also been rewritten, moving from Rust to Swift, while carrying forward the PAM-based credential validation that gave this family its name."
        https://www.jamf.com/blog/pamstealer-wavel-macos-infostealer/
        https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html
      • Been Told To Pay At a Bitcoin ATM? Read This First
        "Many of us still view cryptocurrency as a niche asset. Yet some estimates claim that nearly one in 10 people globally own some. That’s why you may have noticed Bitcoin or crypto ATMs springing up in retail stores, transport hubs, and gas stations over recent years. Today there are tens of thousands in the US alone. Their job is simple: allow you to buy or sell crypto using cash or card. But scammers also have them in their sights. If you ever receive an unsolicited call urging you to deposit money into a crypto ATM, hang up immediately, no matter how serious the allegations. No real government agency, bank, or company will ever tell you to pay them via a Bitcoin ATM."
        https://www.welivesecurity.com/en/scams/been-told-pay-bitcoin-atm-read-first/
      • Threat Actor Profile: Blue Locker Ransomware
        "Blue Locker Ransomware, first detected in late 2021, the group stayed low-profile for years before making global headlines in August 2025 with a targeted attack on Pakistan Petroleum Limited (PPL), the country’s second-largest oil and gas producer. The attack encrypted servers, wiped backups, and brought financial operations to a standstill for two days, prompting Pakistan’s National CERT to issue an emergency advisory to 39 government ministries and institutions. However, attribution remains vague due to competing analyses linking the malware to the Iranian-associated Proton ransomware family on one hand and to an open-source project called MemeCryptor on the other."
        https://socradar.io/blog/dark-web-profile-blue-locker-ransomware/
      • File Acquisition May Be Recorded As “FileAccessed” In Microsoft 365 (“M365”)
        "A recent trend has emerged where threat actor groups (e.g., ShinyHunters, PEAR, HELIX, etc.) have been leveraging phishing and vishing techniques to gain access to M365 email accounts. Through identity and token abuse, these actors have then automated large-scale file exfiltration and extortion campaigns targeting SharePoint, OneDrive, Microsoft Entra ID (formerly Azure AD), and email data through abuse of the Microsoft Graph API. Variations of this playbook have also included leveraging SSO-connected access to third-party platforms (e.g., Salesforce, Jira, etc.) to exfiltrate additional data. Threat actors may also leverage the My Apps page within Microsoft 365, which provides a centralized view of applications available to the user and is frequently used by threat actors to access connected services and applications."
        https://www.levelblue.com/blogs/spiderlabs-blog/file-acquisition-may-be-recorded-as-fileaccessed-in-microsoft-365
      • Beyond The Ransomware: Tracking Storm-2570’s Consistent Tradecraft Across Deployments
        "Activity associated with Storm-2570, a ransomware affiliate linked to multiple ransomware payloads, illustrates how tracking and responding to ransomware attacks by payload alone can obscure the affiliates carrying out intrusions and the recurring behaviors that defenders can use to detect and disrupt them. Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Across multiple investigations, Storm-2570 has maintained largely uniform tradecraft, infrastructure overlaps, and repeated use of the same remote access and cloud exfiltration tooling despite operating across multiple ransomware ecosystems."
        https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
      • The Not So Silent Miner: Threat Actor Compiles Cryptominer On The Endpoint
        "Huntress researchers recently came across a unique incident where, after gaining initial access via exploiting a known Samsung MagicINFO vulnerability and installing a rogue AnyDesk instance on the endpoint, among other things, the threat actor aimed to deploy a cryptominer. Cryptominers in incidents aren't uncommon, but what raised our eyebrows was that the actor in this incident compiled the cryptominer directly on the endpoint. They ran commands via Silent XMR Miner Builder.exe (a Windows builder for deploying a Monero, or XMR, cryptominer, commonly associated with the open-source SilentXMRMiner project) that executed several .NET Framework utilities and an array of C compilers."
        https://www.huntress.com/blog/threat-actor-compiles-cryptominer
      • ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
        "As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint."
        https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
        https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/
        https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html
      • Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
        "The Ontinue Cyber Defence Centre has identified and reverse-engineered a four-stage attack chain associated with the Lunex Malware-as-a-Service platform, targeting Ukrainian-speaking users. The analysed stealer binary was compiled on 12 September 2026, with its supporting infrastructure provisioned shortly beforehand, indicating active development. The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully featured C2 agent. The stealer extracts credentials and data from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and establishes persistent remote filesystem access through a PowerShell-based Native Messaging Host installed within the victim’s browser."
        https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd/
        https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html
      • OpenAI Says Its Models Engaged With US Government Websites In New Model Misbehavior Disclosure
        "OpenAI disclosed Friday that its artificial intelligence agents had interacted with several U.S. government websites in unexpected ways, discovered as part of an ongoing review into the company’s models’ unanticipated behavior. The AI giant’s models accessed publicly available information on two websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data, the company revealed Friday. OpenAI did not find any use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability, the company said."
        https://www.securityweek.com/openai-says-its-models-engaged-with-us-government-websites-in-new-model-misbehavior-disclosure/
        https://securityaffairs.com/199815/ai/openai-agents-accessed-us-government-websites-without-authorization.html

      Breaches/Hacks/Leaks

      • ShinyHunters Hacked Clop Leak Site Using Grav CMS Path Traversal Flaw
        "The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site."
        https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/
      • Hackers Steal $351.6 Million In Bitget Crypto Exchange Hack
        "Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. The company discovered the breach Thursday evening after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets. Bitget has temporarily suspended all withdrawals while investigating the incident with help from law enforcement agencies, on-chain security institutions, and cybersecurity experts at Mandiant and SlowMist."
        https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/
        https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html
        https://therecord.media/crypto-ceo-accuses-north-korea-of-387-million-theft
        https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/
        https://securityaffairs.com/199754/cyber-crime/cryptocurrency-exchange-bitget-says-north-korea-linked-hackers-stole-351-6-million.html
        https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218
      • Cyberattack Hits Welsh Police Force, May Have Affected Staff Data
        "Dyfed-Powys Police in Wales said Friday a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information. The force said it identified the incident earlier this month. It has found no evidence that information belonging to members of the public was affected. The police are still investigating whether information involving employees was accessed or compromised, a spokesperson said."
        https://therecord.media/wales-cyberattack-police-breach

      General News

      • Rydox Marketplace Admin Pleads Guilty, Faces 22 Years In Prison
        "A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. Kosovo law enforcement and Albania's Special Anti-Corruption Body (SPAK) arrested 28-year-old Ardit Kutleshi and two other Rydox administrators (Jetmir Kutleshi and Shpend Sokoli) in December 2024. The arrests were part of a joint international law enforcement operation that also shut down the Rydox marketplace, seized the Rydox[.]cc domain, and seized its servers in Kuala Lumpur with the help of the Royal Malaysian Police."
        https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/
        https://www.securityweek.com/kosovar-owner-of-rydox-marketplace-pleads-guilty-in-us-court/
        https://securityaffairs.com/199825/uncategorized/rydox-admin-faces-20-years-after-selling-stolen-data-and-fraud-tools.html
      • Former U.S. Soldier Sentenced For Hacking And Extortion Scheme That Exposed Sensitive Data Of U.S. Government Official
        "Cameron John Wagenius, 22, a former Army soldier who was most recently stationed in Texas, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to release the stolen data unless ransoms were paid. In November 2024, Wagenius made two online posts that disclosed stolen confidential non-content call detail records belonging to a government official and family members of another former official and threatened to release additional confidential records unless paid a ransom. The text of one of these online posts suggested that Wagenius was motivated by a desire to retaliate for the then-recent arrest of another cybercriminal."
        https://www.justice.gov/opa/pr/former-us-soldier-sentenced-hacking-and-extortion-scheme-exposed-sensitive-data-us
        https://cyberscoop.com/cameron-wagenius-att-snowflake-attacks-sentenced/
      • AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
        "In 1983, WarGames imagined a teenager accessing military systems and nearly triggering a nuclear conflict. The cultural impact was immediate. Congress held hearings, policymakers questioned whether such a scenario was possible, and concerns about computer security entered the mainstream. Forty years later, autonomous AI agents have sparked a similar reaction. Recent disclosures from OpenAI and Anthropic described cybersecurity agents reaching beyond the boundaries of the test environments designed to contain them. The headlines were predictable: AI had "escaped the sandbox.""
        https://www.darkreading.com/cyberattacks-data-breaches/ai-sandbox-escapes-forensic-readiness
      • Stopping IT Worker Scams Requires Revamped HR Process
        "When a suspected North Korean operative applied for a remote AI engineering position at human-risk management firm Nisos in June 2025, the company decided to run its own operation on the fraudster. Nisos notified law enforcement, conducted an HR interview, "hired" the worker, and sent a laptop to that person's US address in Florida — a laptop "farm" — with surveillance implants. "When they opened the laptop, we could see that [the computer was] in a closet with a bunch of other companies' computers," says Ryan LaSalle, the firm's CEO. "We could see it so well that we could see the names of the other companies on the screens across the closet.""
        https://www.darkreading.com/cyber-risk/stopping-it-worker-scams-revamped-hr-process
      • Threat Detection Dashboards Are Masking Security Coverage Gaps
        "A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers assessed 14,652 detections in its customer base, including rules written by customers and detections managed by vendors in SIEM, endpoint, cloud, identity, email and network tools. The research found that 47% of detections in the average organization need attention."
        https://www.helpnetsecurity.com/2026/09/25/threat-detections-coverage-gaps-report/
      • Stop Watching What AI Agents Say And Start Watching What They Do
        "In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot enforce one. Assaraf covers how his team builds AI agent guardrails at the execution layer, limits context without expanding authority, and tunes controls by risk so agents stay useful during incidents. He describes how he tracks the consequences of agent actions, since an agent can return 200s and still do harm."
        https://www.helpnetsecurity.com/2026/09/25/ariel-assaraf-coralogix-ai-agent-guardrails/
      • Your Incident Count Is Missing a Few Incidents
        "If you run security for a brand with hundreds or thousands of locations, the tools you’ve bought may have little to do with whether an attack stays at one store. A new VikingCloud survey asked 200 security and IT leaders at U.S. and European chains about the past year. None of the 13 security technologies it measured was tied to less spread between sites, and neither was real-time visibility. One policy decision was. The sections below cover that decision and why it matters most if franchisees run some of your sites. They also cover how many serious incidents never reach executive leadership, and the exposure that opens with every new store. Eighty percent of these chains open a location before central monitoring and enforcement reach it. The problem is widespread: 86% of respondents were attacked in the past year, and 77% of those saw the attack move past its starting point into other locations, corporate systems, or shared vendors."
        https://www.helpnetsecurity.com/2026/09/25/eu-usa-retail-chain-cyberattacks/
      • Exploit.in Database Reveals The Roots Of Today’s Ransomware Ecosystem
        "Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement press releases don’t. The dump contains 9,647 registered members, 13,925 threads, and 80,891 posts. The researcher who analyzed it had been reading Russian-language forums since those years and expected to recognize the layout. What surprised them wasn’t the marketplace threads selling shells and credit cards next to botnet rental offers. It was how many of the people from 2005 are still on the boards twenty years later."
        https://securityaffairs.com/199800/cyber-crime/exploit-in-database-reveals-the-roots-of-todays-ransomware-ecosystem.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e81ab778-66d4-4f05-b311-2dd8be30a873-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT