NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,567
    • กระทู้ 2,568
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • พบการใช้ช่องโหว่ Fortinet โจมตีอุปกรณ์เพื่อติดตั้งมัลแวร์ PivotC2

      พบการใช้ช่องโหว่ Fortinet โจมตีอุปกรณ์เพื่อติด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d8bc7771-2a8d-4a1e-9361-0d7defac3437-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Trezor เตือนลูกค้าระวัง Phishing หลังผู้ให้บริการ Email ภายนอกถูกเจาะระบบ

      Trezor เตือนลูกค้าระวัง Phishing หลังผู้ให้บริการ Email.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d126ea42-1b7e-4012-b143-7bdaa7cd3ffe-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ในหูฟังไร้สาย Skullcandy Dime 3 เสี่ยงถูกแฮ็กผ่านบลูทูธและดักฟังเสียงโดยไม่ได้รับอนุญาต

      ช่องโหว่ในหูฟังไร้สาย Skullcandy Dime 3 เสี่ยงถูกแฮ็.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 11788b85-8eeb-4b74-8af3-ac776f095371-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 11 September 2026

      Healthcare Sector

      • NextGen Healthcare Mirth Connect
        "Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01
        https://www.bankinfosecurity.com/nextgen-mirth-connect-flaws-expose-downstream-system-logins-a-32789
      • Orthanc DICOM Server
        "Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02

      Industrial Sector

      • AVEVA Pipeline Integrity Monitor
        "Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01

      Vulnerabilities

      • Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
        "Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security Management Server, the console used to configure them. Check Point disclosed the flaws on September 9 in a notice to its customer community, and began delivering fixes the same day. The company says it found both itself and has no indication that either has been used in an attack."
        https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
        CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • Off Guard: Breaking LiteLLM From Authentication Bypass To Cloud Compromise
        "Nearly 1 in 10 publicly accessible LiteLLM instances accept a default master key or require no authentication at all. We found this while scanning roughly 3,000 internet-facing deployments of the most popular open-source LLM gateway. The usual concern with that kind of exposure is LLMjacking -someone using the credentials to run API calls on your bill - however, we wanted to check whether an attacker could do worse than that: could they achieve code execution on the host? Furthermore, could they exploit this to compromise the wider environment? We decided to use Claude Code to work through LiteLLM's codebase, looking for features that accept user-controlled input and pass it to an execution context. We found multiple issues, as detailed below."
        https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypass-to-cloud-compromise
        https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html

      Malware

      • Mantax Otax: Indonesian Mobile Ransomware With Spyware Integration
        "The zLabs research team has discovered a sophisticated and highly aggressive mobile malware strain linked to Indonesian threat actors, that marks a dangerous tactical evolution by seamlessly integrating comprehensive spyware capabilities with traditional ransomware functionality into a single attack vector. This hybrid threat systematically compromises user privacy through an intrusive suite of surveillance features, which includes recording device screens in real-time, extracting browser history, stealing lock screen PINs, harvesting contact lists, call logs, and SMS messages, exfiltrating local files, and capturing unauthorized photographs."
        https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
        https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
        https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign
        https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/
      • CISA: WatchGuard RCE Flaw Now Exploited In Ransomware Attacks
        "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. This flaw is tracked as CVE-2025-14733 and stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks. This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3."
        https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/
      • PuzzleMask: The Prompt Injection Hiding In Plain Sight
        "Most prompt injection detection is built to catch the obvious. Encoding anomalies, invisible unicode, emoji smuggling, the signatures a classifier can pattern match against. PuzzleMask, a newly disclosed technique, sidesteps all of it. It embeds a policy-violating payload inside fluent, properly punctuated prose, and gets that payload past an LLM-based gatekeeper without tripping any heuristics naively looking for obfuscation on the input side."
        https://blog.checkpoint.com/security/puzzlemask-the-prompt-injection-hiding-in-plain-sight/
        https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/
      • False Allegations, Real Threats: Sexual Misconduct Claims Used As Phishing Lures
        "Threat actors are impersonating leaders of partner universities in emails alleging a sexual misconduct violation has occurred, using sensitive claims to trick victims into installing abused, technically legitimate Remote Access Tools (RATs) on their computers. The alleged misconduct case is entirely fabricated, serving as a façade for delivering malware."
        https://cofense.com/blog/false-allegations,-real-threats-sexual-misconduct-claims-used-as-phishing-lures
      • From Infostealer Log To Marketplace Listing: A Technical Walkthrough Of The Credential Theft Pipeline
        "Infostealer malware is behind a large share of today’s credential compromise — and it usually doesn’t start with a breach at all. When a security team hears “data breach,” the instinct is to look for the moment a database was exfiltrated or a network was penetrated. But more often, the real starting point is a single endpoint infection, often on a personal device, that has nothing to do with the organization’s perimeter. By the time stolen credentials show up in a breach notification or a dark web alert, they’ve already passed through several distinct, mechanical stages. Understanding that pipeline — rather than waiting for the final alert — is what separates reactive security teams from ones that catch exposure early."
        https://cyble.com/blog/infostealer-malware-credential-theft-pipeline/
      • Passkey-Themed Social Engineering Leads To Identity And Cloud Compromise
        "Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. Microsoft Security Research assesses that this sequence is consistent with automated collection from compromised cloud identities using proxy-associated infrastructure, the activity has been observed since May 2026."
        https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/
        https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data
        https://www.helpnetsecurity.com/2026/09/10/microsoft-365-social-engineering-personal-phones/
      • Casbaneiro: A Banking Trojan With Distributed Data-Receiving Servers
        "In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. Casbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use of fake windows to facilitate fraudulent activities. However, our analysis of the recent attack revealed several distinctive network behaviors that differentiate this campaign from previously observed Casbaneiro behavior."
        https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers
      • Grand Theft Auto VI Hype Leads To Malware
        "Threat actors are taking advantage of overeager gamers searching for a leaked version of the upcoming Grand Theft Auto VI (GTA6), using fake game downloads as an initial access lure. Huntress has seen several examples of SEO poisoning designed to rank highly in searches for GTA6, as well as ISOs published on gaming forums, social media, and various torrenting sites. Huntress analyzed an ISO file masquerading as a leaked version of GTA6 found in a sandbox. The package includes a fake installer, several RATs, an infostealer, ransomware being used as a wiper, and a web browser. Based on the language in the initial prompts and eventual ransom note, the malware appears to be targeting Russian gamers."
        https://www.huntress.com/blog/fake-gta6-download-malware-analysis
        https://www.helpnetsecurity.com/2026/09/10/fake-gta-6-downloads-malware-ransomware/
      • SloppyRAT: A New Tool For Ransomware Attacks
        "In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques. Beyond SloppyRAT’s capabilities, the malware is notable because the codebase includes numerous software flaws, which suggest that it is still under development."
        https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
      • Google Play's Early Access Program May Be Exploited By Potentially Deceptive Apps
        "An analysis of Google Play apps installed by Bitdefender users reveals thousands of Early Access applications that appear to include fake casino games and reward apps, as well as titles that may infringe on third-party trademarks and potentially misleading utilities. Many are aggressively promoted through TikTok, Facebook, and other social media platforms using misleading advertisements that include videos using AI-generated celebrity deepfakes. The result is an ecosystem in which consumers have almost no way to warn one another before installing questionable software."
        https://www.bitdefender.com/en-au/blog/hotforsecurity/google-play-early-access-exploit-deceptive-apps
        https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html
        https://www.securityweek.com/deceptive-android-apps-exploit-google-play-early-access-to-evade-reviews/
      • Trezor Warns Users Of Email Provider Breach, Phishing Attacks
        "Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. Affected customers received fake "critical security alert" emails from [email protected] claiming that a "hardware microcontroller vulnerability" in the STM32 microcontrollers used by Trezor cold storage wallets could expose their seeds to brute-force cracking. The company said that it's investigating the breach and that the domain has been taken down to stop the attacks."
        https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/
        https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
        https://www.helpnetsecurity.com/2026/09/08/trezor-shipping-partner-breach-phishing-attacks/
      • The Machine With Many Faces: Post-Exploitation Identity Misuse In SPIFFE/SPIRE
        "This research demonstrates post-exploitation techniques that could allow an attacker with root access on a compromised Kubernetes node to misuse an open standard and reference implementation for machine identity known as SPIFFE/SPIRE to impersonate co-located workloads and harvest SPIFFE Verifiable Identity Documents (SVIDs). We show how the trust assumption at the core of every machine-identity system — that the node is trusted — collapses once an attacker obtains root on that node. Unit 42 has not observed this technique exploited in the wild."
        https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/
      • CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
        "One of the most common entry points for attackers is the exploitation of public-facing edge devices (such as VPNs, routers, and firewalls). Over the years, FortiGate firewalls have remained a consistent target, as evidenced by the recent widespread FortiBleed campaign conducted jointly by the INC and Lynx ransomware groups. The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon. Successful exploitation delivers PivotC2, a Node.js Remote Access Trojan (RAT) designed specifically as a FortiGate post-exploitation tool. PivotC2 supports features such as interactive shells, tunneling, network scanning, and configuration harvesting."
        https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
        https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/
      • Shai-Hulud Rises From The Dead After 111 Days
        "Hello internet, Do you remember the Shai-Hulud attack that hit @AntV on May 19th, 2026? I know, it feels like a lifetime ago by now in the supply chain world. A compromised maintainer account pushed 639 malicious versions of @antv packages to npm in a single hour. We, along with most of the npm security community, tore that payload apart within hours. It was nothing novel, technique-wise. It was just another day of waking up and there being a supply chain attack. Business as usual."
        https://www.aikido.dev/blog/shai-hulud-npm-resurfaces

      Breaches/Hacks/Leaks

      • Surfshark VPN Says Hackers Breached Internal Testing, Proxy Servers
        "Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed service configurations and build-related credentials. “Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” Surfshark explained on its website."
        https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/
      • An Alignment Assessment Of Recent Cybersecurity Incidents
        "We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems. We described three of these incidents on July 30; we identified these after a scan of roughly 141,000 transcripts in which we believed Claude could have obtained internet access during a cyber evaluation. Given the volume of transcripts and our desire to disclose incidents quickly, our scan relied on an agentic search. This missed a set of transcripts that also turned out to have internet access; we identified these in August while assembling transcripts to share with METR. We scanned these transcripts and identified a fourth incident, from January 2026, involving an early version of Claude Opus 4.6. We have notified all affected parties."
        https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents
        https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html
        https://www.infosecurity-magazine.com/news/anthropic-another-cybersecurity/
        https://www.theregister.com/ai-and-ml/2026/09/10/anthropic-reveals-fourth-likely-crime-committed-by-its-ai/5295412
        https://www.securityweek.com/widened-scan-turns-up-fourth-rogue-claude-cyber-incident/
        https://securityaffairs.com/198814/hacking/a-new-claude-s-sandbox-failure-shows-how-ai-can-rationalize-real-world-harm.html
      • IDScan Confirms Breach After Hackers Offer 153 Million Driver’s License Scans For Sale
        "Identity verification firm IDScan said hackers obtained customer data held in its cloud platform following recent reports connecting the company to a database breach exposing scans of some 153 million driver’s licenses. The company confirmed a hack in a notice published on its website on September 4 and said it became aware of the breach on or around September 1 — the same day a journalist reported the news based on dark web activity."
        https://therecord.media/idscan-data-breach-notice-drivers-licenses
        https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/
      • ShinyHunters Expose 6.4M In Attack On Medical Supplier McKesson
        "McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP did not confirm that figure."
        https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/5295550

      General News

      • Ukrainian National Sentenced To Four Years In Prison For Wire Fraud Conspiracy In Connection With Conti Ransomware
        "Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000 victims worldwide. According to court documents, Lytvynenko, formerly of Cork, Ireland, conspired with others to deploy Conti ransomware to extort victims and steal their data. From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000."
        https://www.justice.gov/opa/pr/ukrainian-national-sentenced-four-years-prison-wire-fraud-conspiracy-connection-conti
        https://cyberscoop.com/conti-ransomware-developer-sentenced/
      • Detecting And Countering Misuse Of AI: September 2026
        "Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate."
        https://www.anthropic.com/threat-intelligence-report-september-2026
        https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
        https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/
      • AI Adoption Brings New Security Headaches For Already Stretched CISOs
        "CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report. GenAI is creating new concerns around sensitive data, access and employee activity. Seventy-eight percent of CISOs consider it a security risk, with the potential loss of customer data through public AI platforms a key concern."
        https://www.helpnetsecurity.com/2026/09/10/proofpoint-ciso-ai-security-risks-report/
      • CISA Updates Insider Threat Guide With New Mitigation Advice
        "The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Insider Threat Mitigation Guide with new case studies, statistics and guidance on hybrid and remote work, artificial intelligence and adverse employee separations. The agency published the revision on September 9. First issued in 2020, the guide supports security and human resources professionals who run insider threat programs, along with leaders at any level, and CISA said any organization can use it regardless of the maturity of its security."
        https://www.infosecurity-magazine.com/news/cisa-updates-insider-threat-guide/
      • More Capable AI, Not Enough Guardrails
        "Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this week with a blunt warning: AI companies are moving toward increasingly capable systems faster than they can build reliable safeguards around them. I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below."
        https://securityaffairs.com/198833/ai/more-capable-ai-not-enough-guardrails.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 00cac1d3-ee2b-4f03-b209-cc9ded07c652-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 10 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
      • CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd97e004-14d0-4651-b264-9352948152c6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ เมื่อวันที่ 10 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      ICSMA-26-253-01 NextGen Mirth Connect
      ICSMA-26-253-02 Orthanc DICOM Server
      ICSA-26-253-01 AVEVA Pipeline Integrity Monitor
      ICSA-26-183-01 ST Engineering iDirect iQ-Series Terminals (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 79d6973d-9d0c-4173-85fe-31aec01f48ec-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 8 รายการลงในแคตตาล็อก

      เมื่อวันที่ 8-9 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 8 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
      • CVE-2026-81963 Microsoft Windows Link Following Vulnerability
      • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
      • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
      • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
      • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
      • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
      • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 501a514a-b633-4249-8113-0ea4d282fa64-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบเครือข่ายร้านค้าออนไลน์ปลอม DoppelCart ใช้กว่า 119,000 โดเมน หลอกขโมยข้อมูลบัตรชำระเงิน

      พบเครือข่ายร้านค้าออนไลน์ปลอม DoppelCart ใช้กว่า 119,000 โดเมน หลอกขโมยข้อมูลบัตรชำระเงิน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd5e4a01-a3ac-4763-b1eb-d5be9a1ac387-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบ Plex Media Server กว่า 36,000 เครื่องเปิดสู่อินเทอร์เน็ต ยังไม่ได้แพตช์ช่องโหว่ล่าสุด

      พบ Plex Media Server กว่า 36,000 เครื่องเปิดสู่อินเทอร์เน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7b1ba684-04b8-4a37-84f0-1e4213bfe1c1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบแคมเปญ Phishing อาศัยบริการของ Google สร้างลิงก์ส่งต่อหลายทอดเพื่อขโมยข้อมูลและควบคุมเครื่อง

      พบแคมเปญ Phishing อาศัยบริการของ Google สร้างลิงก์ส.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ec8cec7e-88dd-44ae-9b63-6f62af7aa697-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 10 September 2026

      Industrial Sector

      • ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
        "Industrial giants Schneider Electric, Siemens, and Aveva have published September 2026 Patch Tuesday advisories, informing customers about vulnerabilities found in their ICS products. Schneider Electric published four new security advisories and updated four others, including one originally released in 2019. The most severe of the newly addressed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. Tracked as CVE-2026-3869, the flaw has a CVSS score of 9.2."
        https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/

      New Tooling

      • AI-Infra-Guard: Open-Source Security Scanner For AI Systems
        "Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak evaluations against a target model. To check a skill, the platform asks a language model whether it looks malicious. Zhuque Lab scores that call against SkillTrustBench, a public set of 5,520 human-labeled samples across nine risk categories. False positive rates there run from 1.20 percent to 18.67 percent, depending on which model does the judging."
        https://www.helpnetsecurity.com/2026/09/09/ai-infra-guard-open-source-security-scanner-ai-systems/
        https://github.com/Tencent/AI-Infra-Guard

      Vulnerabilities

      • Active Exploitation Of Cisco Secure Firewall Management Center Vulnerabilities
        "Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account."
        https://blog.talosintelligence.com/fmc-ongoing-exploitation/
        https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
      • Fortinet Patches Critical Vulnerabilities In FortiMonitorOnSight, Chrome Extension
        "Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including critical security defects. The first critical bug, tracked as CVE-2026-84390 (CVSS score of 9.6), is described as an inclusion of sensitive information in source code issue affecting the FortiMonitorOnSight web portal. A remote, unauthenticated attacker could exploit the flaw to bypass authentication via a forged or reused JSON Web Token (JWT). The second critical vulnerability is an improper authentication issue in the Fortinet Privileged Access Agent Chrome extension, tracked as CVE-2026-84388 (CVSS score of 9.1)."
        https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/
      • Ivanti Patches Critical Flaws Across Enterprise Security Products
        "Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products. Neurons for ITSM received fixes for the largest number of security defects. Of the eight bugs, six are critical-severity issues that could lead to remote code execution, Ivanti warns. These include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (CVSS score of 9.9/10), described as missing authorization issues; and CVE-2026-12650 (CVSS score of 9.9/10), CVE-2026-12744, and CVE-2026-12745 (CVSS score of 9.8/10), described as deserialization of untrusted data weaknesses."
        https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/
      • Google Fixes Yet Another Actively Exploited Chrome Zero-Day (CVE-2026-87491)
        "Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been shipped in Chrome 153.0.8010.36 and .37 for Windows and macOS and Chrome 153.0.8010.36 for Linux."
        https://www.helpnetsecurity.com/2026/09/09/google-chrome-cve-2026-87491-zero-day-flaw/
        https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/
        https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
        https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/
        https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-exploited-chrome-zero-day-of-2026.html
      • DeepSeek Harness < 0.1.2-Alpha.1 Authentication Bypass Via Host Header Spoofing
        "DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key."
        https://www.vulncheck.com/advisories/deepseek-harness-alpha-1-authentication-bypass-via-host-header-spoofing
        https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html
      • Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
        "Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through v1.18.5, all released before August 2025, and Alby said one user has been affected so far."
        https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
        CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
        CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
        CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog
      • Skullcandy Dime 3 Wireless Earbuds Contain An Unauthenticated Bluetooth Pairing Vulnerability
        "Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from the owner."
        https://kb.cert.org/vuls/id/859658
        https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/
      • Over 36,000 Exposed Plex Servers Vulnerable To Recent Flaws
        "Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking. While the company didn't provide additional details on Tuesday when it issued the warning, these security flaws are known to affect Plex Media Server v1.43.2 and earlier."
        https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/
      • New Microsoft Defender 'ShieldCrash' Zero-Day Grants SYSTEM Access
        "An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself bypassed RoguePlanet, another Defender flaw disclosed in June and patched by Microsoft in July."
        https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/
        https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html
        https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html
        https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335
      • Android’s September 2026 Updates Patch 180 Vulnerabilities
        "After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates. As usual, the updates are split into two parts. The first part arrives on devices as the 2026-09-01 security patch level and resolves 95 bugs across Android runtime, Framework, System, Setup Wizard, and multiple Project Mainline components (patched via Google Play system updates). “The most severe of these issues is a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation,” Google notes in its advisory."
        https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/
      • Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
        "Major chipmakers AMD, Arm, and Nvidia published new security advisories on Tuesday to notify customers of vulnerabilities recently discovered in their products. AMD announced fixes for CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could lead to system crashes and a denial-of-service (DoS) condition. The company credited Maxime Rossi Bellom and Ramtine Tofighi Shirazi from SecMate for reporting the security defect."
        https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/
      • New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code As Root
        "cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected. The flaw is tracked as CVE-2026-67401. cPanel's advisory calls it an SQL injection issue in EmailTrack, but does not say which cPanel feature or privilege an account needs. cPanel's developer documentation lists an EmailTrack module that tracks email statistics, and the advisory does not say whether that is the affected code."
        https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html
      • One Blank Field Bypasses Direct Send Control
        "ReliaQuest observed that an empty Simple Mail Transfer Protocol (SMTP) envelope sender can bypass RejectDirectSend, a Microsoft 365 control in Exchange Online intended to block unauthenticated Direct Send emails from an organization’s domain. An external sender can omit the envelope domain while retaining an internal-looking address, making phishing messages more likely to be trusted. Direct Send allows devices and applications to send email to recipients in the same Microsoft 365 tenant without authentication. RejectDirectSend evaluates the domain in the SMTP envelope sender, but an empty value means there’s no domain to check. In testing, changing only this field caused Microsoft 365 to accept and queue a message it otherwise rejected."
        https://reliaquest.com/blog/threat-spotlight-one-blank-field-bypasses-direct-send-control

      Malware

      • Once In a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome And Windows Zero-Days
        "Beginning in late August and continuing into September 2026, Proofpoint identified multiple espionage-motivated threat actors rapidly adopting the BlueMoon exploit kit in targeted spearphishing campaigns. Several characteristics of this activity are consistent with a capability that was opportunistically adopted and deployed ahead of an anticipated patch. While the chain exploited vulnerabilities present in the latest stable versions of Chrome and Chromium-based browsers (such as Microsoft Edge), it was paired with a Windows LPE vulnerability present only in older Windows builds. This pairing substantially narrows the pool of viable targets and reduces the chain's overall probability of success."
        https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit
        https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html
        https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups
        https://cyberscoop.com/china-espionage-groups-exploit-chain-zero-days/
        https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399
      • Workflow Identity Hijacking: The Silent Backdoor In AI Workflows
        "An attacker sends a benign message to a company’s public support email. Minutes later, the attacker receives the quarterly sales numbers from the Finance Director's most recent email. The company's AI workflow read the message, understood the request, searched for the requested information, and replied. No prompt injection was required, no account was breached, and no workflow was hijacked. All the attacker had to do was ask."
        https://noma.security/noma-labs/workflow-identity-hijacking-the-silent-backdoor-in-ai-workflows
        https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data
      • Vwork: Weaponized Open-Source Software As An Addon For Gigabud
        "During the “Hook for Gold” research, Group-IB discovered an application called Vwork that was installed within minutes after initial Gigabud infection along with tampered banking applications. Trials to find a sample of Vwork lead to Gigabud samples that are intentionally built to interact with Vwork. The significance of this finding meant that Vwork on infected devices cannot be considered a coincidence anymore. This article reveals what Vwork is, and how it is related to Gigabud."
        https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
        https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/
      • Threat Spotlight: Phishing Pages That Exist Only Inside The Victim’s Browser
        "Most phishing campaigns rely on a hosted webpage that security tools can retrieve, analyze, categorize, and eventually block. A recent campaign analyzed by Barracuda researchers breaks that model. Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website. By the time the phishing page appears, the victim has already been routed through legitimate Microsoft services, including Microsoft OAuth and Microsoft Teams, with little visible indication that anything malicious is taking place."
        https://blog.barracuda.com/2026/09/09/browser-based-phishing-blob-urls-microsoft-redirects
        https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/
      • Signing In Without Actually Signing In
        "The price of AI tokens and subscriptions is increasing as AI model providers seek to recoup investment costs. As a result, these accounts are becoming more valuable targets for account takeover. Stopping this is paramount for enterprises. AI theft increases token bills. In three recent cases, it was to the tune of nearly $1 million for one organization, a shock $25,000 bill for a software architect and $600,000 in AI credits for an AI testing organization due to a stolen API key. Some AI providers are detecting this abuse and automatically logging affected users out and removing their payment cards on record to limit the damage. Malware developers and phishing operators have shown interest in applying AI to their operations, and attackers have been documented using stolen AI inference."
        https://www.okta.com/blog/threat-intelligence/signing_in_without_actually_signing_in/
        https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
      • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
        "A recent Unit 42 investigation into seemingly low-priority enterprise infections demonstrates how the most effective camouflage in cybercrime is not necessarily in the use of sophisticated techniques, but in how unremarkable the threat appears. The activities that we investigated would typically not require escalation or further inquiry. But upon closer inspection, we discovered a massive cybercrime campaign largely targeting young gamers. Tracked as CL-CRI-1171, in accordance with Unit 42’s attribution framework, the group behind this cluster has operated under the radar for at least two years, distributing an indeterminate number of payloads."
        https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
      • Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
        "GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise has been tracking malicious use of 45[.]142[.]193[.]132 since early July 2026 due to its use for attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE."
        https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf

      Breaches/Hacks/Leaks

      • AdaptHealth Confirms 4.1 Million People Exposed In July Cyberattack
        "Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. AdaptHealth first disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, informing that attackers accessed its systems and exfiltrated private data."
        https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/
      • Veradigm Warns Of Patient Data Breach After Ransomware Gang Claims Attack
        "Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software."
        https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/
        https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach

      General News

      • August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges As a New Enterprise Risk As Attacks, Phishing, And Ransomware Accelerate
        "August showed that cyber risk is intensifying on multiple fronts at once. Global attacks continued to rise, ransomware volumes accelerated, and phishing remained a consistent entry point for threat actors. GenAI added a more nuanced but equally important signal: while August recorded the lowest rate of high-risk for data exposure in GenAI prompts in several months, enterprise AI usage continued to expand sharply, with the average number of prompts per user rising from around 78 in June to 95 in July and 106 in August."
        https://blog.checkpoint.com/security/august-2026-cyber-threat-landscape-genai-data-exposure-emerges-as-a-new-enterprise-risk-as-attacks-phishing-and-ransomware-accelerate/
      • FBI Officials Say AI Is Bolstering Adversaries, Emphasizing Need To Focus On Cyber Basics, Patching
        "Artificial intelligence is souping up the speed and capabilities of malicious hackers, a top FBI official said Tuesday. And the speed of vulnerability discoveries is forcing organizations to patch more frequently, said another top FBI official. The officials made their remarks one day before the release of a new FBI cyber strategy Wednesday, which touches on AI, relief and justice for victims and other bureau priorities. Speaking to both CyberScoop and at the Billington CyberSecurity Summit, Jason Bilnoski, deputy assistant director of the FBI’s cyber division, said AI is “taking actors to the next level.”"
        https://cyberscoop.com/fbi-cyber-strategy-ai-threats-patching/
      • The Anthropic Glasswing Receipts Are Starting To Trickle In
        "Anthropic’s Project Glasswing is approaching 5 months old, and Anthropic published its Vulnerability Disclosure Ledger on May 22nd. It hadn't received an update until this past week, when it backfilled the ledger with additional findings and updates, so naturally I thought it would be worthwhile to take a look at the receipts. For a bit more context, I've been tracking Project Glasswing since they launched the project on April 7, and have published a series of blog posts covering the project:"
        https://www.vulncheck.com/blog/anthropic-glasswing-receipts
        https://www.darkreading.com/application-security/mythos-vulnerability-firehose-hits-human-bottleneck
      • Gartner: 70% Of SOCs Will Pilot AI Agents. Only 15% Will See Results
        "In the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment Tier 1 and Tier 2 operations, but only 15% will achieve measurable improvements without structured evaluation.” Just last year, Gartner placed AI SOC Agents at the Innovation Trigger stage with single-digit adoption. As of earlier this year, Gartner’s Hype Cycle for Security Operations, 2026 put them at the Peak of Inflated Expectations."
        https://www.helpnetsecurity.com/2026/09/09/prophet-security-evaluating-ai-soc-agents/
      • 2026 SpyCloud Identity Threat Report
        "Identity exposure is measurable and fixable – yet most organizations are still navigating with an outdated map, drawn for marked trails rather than the backcountry attackers now roam. The terrain has expanded past employee credentials to session tokens, non-human identities, and third-party ecosystems, and closing the gap means surveying what’s exposed beyond the camp’s edge before attackers get there first. This year’s Identity Threat Report [1] – a survey of security leaders and practitioners across North America, UK and select European Markets – benchmarks how enterprise organizations detect, remediate, and govern identity threats – and what separates the most mature programs from the rest."
        https://spycloud.com/resource/report/identity-threat-report-2026/
        https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/
      • This Key Will Self-Destruct: An Open Standard For Revocable API Keys
        "Every security leader has lived some version of this incident. A researcher, a scanner, or a well-meaning stranger finds one of your API keys sitting in a public repository. Now the clock is running, but instead of a kill switch, what follows is a scavenger hunt. Which company issued this key? Who do I contact? Is there a security.txt? Does anyone read that inbox? By the time the right person revokes the right credential, hours or days have passed, and attackers needed minutes. Bots scrape public repos constantly, and the majority of leaked secrets are still active years later."
        https://www.securityweek.com/this-key-will-self-destruct-an-open-standard-for-revocable-api-keys/
      • Scam Center Strike Force Conducts Seizures Of Chinese-Run Illicit Scammer Marketplace, And Restrains $52 Million In Laundered Crypto Scammer Funds In One Day
        "U.S. Attorney Jeanine Ferris Pirro, together with major federal law enforcement and interagency partners, announced actions taken by the Department of Justice’s Scam Center Strike Force to secure America against Southeast Asian cryptocurrency-related fraud and scams. The Strike Force and the Department of the Treasury took coordinated actions against Xinbi Guarantee (“Xinbi”), an illicit marketplace for scam services, and the Strike Force deployed to Madagascar to assist in the taking down of 13 Chinese-run scam compounds. Approximately $52 million of cryptocurrency involved in scam money laundering was restrained in one day, bringing the total restrained by the Scam Center Strike Force to approximately $938 million."
        https://www.justice.gov/usao-dc/pr/scam-center-strike-force-conducts-seizures-chinese-run-illicit-scammer-marketplace-and
        https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html
        https://therecord.media/us-disrupts-xinbi-guarantee-marketplace-cybercrime

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c1c561a3-1bce-4607-94f6-362419364e87-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 09 September 2026

      Industrial Sector

      • CareCam Pro IP Cameras
        "Successful exploitation of this vulnerability could allow an attacker to take full control of the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01

      Vulnerabilities

      • Microsoft September 2026 Patch Tuesday Fixes 966 Flaws, 2 Zero-Days
        "Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass."
        https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
        https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/
        https://www.darkreading.com/vulnerabilities-threats/patch-tuesday-another-record-974-cves
        https://therecord.media/microsoft-patch-tuesday-september-2026
        https://cyberscoop.com/microsoft-patch-tuesday-september-2026/
        https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/
      • SAP Warns Of Maximum Severity 'OVERPASS' Kernel Vulnerability
        "SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of the underlying SAP processes and business data."
        https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/
        https://onapsis.com/blog/sap-overpass-remediation/
        https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/
      • Adobe Fixes Critical Magento Zero-Day Exploited To Backdoor Servers
        "Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites. The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server. However, it still leaves distinct signs of activity on compromised hosts, such as "Payment Transaction Failed Reminder" emails."
        https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/
        https://helpx.adobe.com/security/products/magento/apsb26-146.html
        https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
      • Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
        "Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE)."
        https://www.securityweek.com/adobe-patches-over-170-vulnerabilities-including-commerce-zero-day/
      • FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
        "A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The FreeIPA project has already fixed its side in version 4.13.4. Red Hat says it reproduced the chain twice on a default installation, most recently on a machine with no access at all."
        https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
        CVE-2026-81963 Microsoft Windows Link Following Vulnerability
        CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
        CVE-2026-86218 N-able N-central Static Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog

      Malware

      • China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
        "China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
        https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/
        https://www.bankinfosecurity.com/us-warns-chinese-ai-firms-are-illicitly-distilling-models-a-32773
      • DoppelCart: 119,000 Domains In What May Be The Largest Documented Fake-Shop Network
        "Around 119,000 domains, connected by shared infrastructure and recurring features in their shop software. Product catalogs from real businesses, copied descriptions and original images. And customers whose complaints end up with the legitimate store. We investigated a fake-shop network whose scale surprised even us. We call it DoppelCart. To our knowledge, DoppelCart is the largest fake-shop cluster publicly documented to date, measured by the number of associated domains. Its .shop domains alone account for 2.72 percent of the .shop domain population in our snapshot. That is roughly one in every 37 domains."
        https://nebty-id.com/en/doppelcart-fake-shop-network/
        https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/
      • Dissecting a PHP Web Server Rootkit
        "SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells. The implant delivers a familiar outcome – on-demand server‑side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache‑specific tradecraft."
        https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit
        https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/
      • ClearFake WebDAV Infection Chain Delivers Amatera Stealer, ZigCryptoStealer, And NetSupport Manager
        "Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating Google CAPTCHA, leading to download and execution of Amatera stealer. The chain is likely very similar to what has caused the WebDAV-based execution at the Ukraininan government organization."
        https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
      • ClickFix Moves Into The Browser: Cryptocurrency Theft With Google-Hosted C2
        "Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the Tampermonkey browser extension, which also provides persistence."
        https://blog.talosintelligence.com/clickfix-moves-into-the-browser/
        https://www.darkreading.com/endpoint-security/clickfix-campaigns-legitimate-services-persistent-access
      • Bypassing The Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure Into a Trust Proxy
        "In addition to everyday users, Google's infrastructure is trusted by email security gateways, enterprise firewalls and automated URL detonation platforms. Threat actors know this. In this KnowBe4 Threat Lab analysis, we break down an active, wide-scale phishing campaign that routes victims through a deliberate chain of legitimate Google services before landing them on credential harvesters or deploying remote access tools. The execution here is unusually complete: six distinct Google properties abused across multiple redirect paths, a landing page that dynamically impersonates the victim's own organization in real time, and a dual-track post-redirect architecture that delivers either credential theft or persistent remote access depending on the lure context."
        https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy
        https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign
      • Hagaseca: Inside a Packed Android RAT Loader
        "Hagaseca is an Android malware cluster associated with exposed Android Debug Bridge (ADB) services. This analysis examines the Hagaseca Android RAT loader known as THost9. RAT stands for remote access trojan. A RAT can let an attacker control an infected device remotely. The loader hides executable code inside an Android application package (APK). It then loads tc9.dex, a separate stage with shell access, file transfer, and ADB propagation capabilities."
        https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
        https://www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/
      • WeWorm
        "At Calif, our mission is to keep the Internet together by occasionally taking it apart. We believe everyone deserves a safe and secure Internet, including the people who cannot protect themselves. Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. This is the first installment in a series exploring zero-click attack surfaces in mobile messaging apps. WeChat is an "everything app" used by virtually everyone in China and by Chinese communities worldwide. Simply by calling a victim, WeWorm can hijack their account and call their friends, spreading from phone to phone. If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide."
        https://calif.io/research/weworm
        https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html
        https://securityaffairs.com/198688/hacking/wechat-worm-can-hijack-accounts-without-victims-answering-calls.html
        https://www.helpnetsecurity.com/2026/09/08/wechat-weworm-vulnerability-exploit-account-hijacking/
      • Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
        "A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities' cloud environments," CrowdStrike said."
        https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html
        https://go.crowdstrike.com/rs/281-OBQ-266/images/CrowdStrike-2026-Threat-Hunting-Report.pdf
      • BengalSEO Part 1: Anatomy Of The Operation
        "In March 2026, our team identified an SEO poisoning campaign leading to malware deployment and tech support scams. Further research into this campaign revealed a sophisticated and widespread scam operation that has been operating since at least 2015. Our team attributes this operation, with high confidence, to a group of core individuals and IT service providers operating out of Rajasthan, India, which our team tracks collectively as BengalSEO. Using indicators gathered from the identified SEO poisoning campaign, our team was able to correlate this activity with information posted on scam hunting forums. This discovery led our team to a company named WeConnect Solutions LLC (previously iConnect Soft Solutions LLC), which operates a tech support call center located in Kota, Rajasthan."
        https://thedfirreport.com/2026/08/24/bengalseo-part-1-anatomy-of-the-operation/
        https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html
      • Anatomy Of a Layered, Multi-Brand Phishing Campaign
        "Barracuda Research has analyzed a multi-layered, multi-brand phishing campaign that reflects a trend for attackers to embed authentication requests inside familiar business workflows. Similar to platforms such as Kali365, which we recently reported on, the objective is to make authentication appear a routine step in a document-sharing, signing or collaboration process. However, unlike Kali365’s device-code phishing and token-focused attacks, this campaign relies on browser-in-the-browser (BitB) deception to harvest credentials directly."
        https://blog.barracuda.com/2026/09/08/browser-in-the-browser-phishing-docusign-adobe-microsoft

      Breaches/Hacks/Leaks

      • ShinyHunters Hackers Claim Breach Of Florida "DAVID" DMV Database
        "The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. As proof of the breach, the threat actor has released a screenshot of Jeffrey Epstein's DMV record, including his address and registered vehicles. DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver."
        https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
        https://hackread.com/shinyhunters-florida-dmv-breach-jeffrey-epstein-proof/
      • 220 Million Traveler Records Exposed In Vietnam-Linked APIS Leak
        "An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it. Advance Passenger Information Systems are used worldwide to collect identity, passport, and flight information from airlines before passengers and crew arrive at or depart from a country."
        https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/
        https://securityaffairs.com/198671/data-breach/massive-vietnam-linked-apis-database-exposes-passport-and-flight-data.html
      • Cyberattack Encrypts Systems At Bavarian Municipal Utility
        "A municipal utility in Bavaria said Monday that hackers encrypted its central IT network in a cyberattack last week. In a notice to customers, Stadtwerke Landsberg said the attack disrupted office systems but is not affecting electricity, water and other essential services. The incident began overnight on September 1, the utility said, prompting it to disconnect the affected systems from the internet, activate its crisis team and bring in external cybersecurity specialists."
        https://therecord.media/cyberattack-bavaria-germany-utility

      General News

      • GTIG AI Threat Tracker: From Prompting To Autonomy – The Evolution Of Adversarial AI
        "Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours. We also tracked UNC6780 using multiple tactics to trick AI coding assistants and large language model (LLM) security scanners into its open source software supply chain compromises."
        https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai
        https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
        https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html
        https://www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/
        https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640
        https://www.helpnetsecurity.com/2026/09/08/ai-agents-cyberattacks-automation-google-research/
      • ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts
        "Enterprises are connecting AI assistants to more of their real infrastructure every month, from inboxes to file drives to internal tools, on the assumption that the isolation between users and accounts holds. Check Point Research just tested that assumption against ChatGPT and found a way to break it. Using an internal service that was never meant to carry user data at all, CPR opened a working channel between two completely separate ChatGPT accounts and used it to hand one victim’s session a task from a total stranger, all while the victim’s own conversation looked entirely normal."
        https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/
        https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
        https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html
      • Russian National Extradited To United States For Bank Account Takeover Fraud Scheme Causing Millions Of Dollars In Losses
        "Sergei Anatolyevich Filimonov, 36, a Russian national and web developer who was allegedly involved in a transnational cyber‑fraud conspiracy responsible for large‑scale bank account takeover activity, was arraigned Friday in the Northern District of Georgia after being extradited from the Republic of Georgia. Filimonov was indicted by a federal grand jury on Nov. 4, 2025, for charges relating to a credential‑harvesting and bank‑fraud operation that targeted victims across the United States."
        https://www.justice.gov/opa/pr/russian-national-extradited-united-states-bank-account-takeover-fraud-scheme-causing
        https://therecord.media/russian-cybercrime-bank-extradition
        https://cyberscoop.com/russian-national-extradited-bank-account-takeover-sergei-filimonov/
      • Scammer Behind $245 Million Crypto Heist Pleads Guilty To RICO Charges
        "A Singaporean national pleaded guilty to racketeering charges on Tuesday for his role leading a group of scammers who stole more than $245 million in cryptocurrency. Malone Lam, 22, will appear in U.S. District Court in Washington D.C. on December 8 for more information on sentencing. Participating in a RICO conspiracy charges carry sentences ranging from 7 to 20 years. Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets. Prosecutors said Lam, known as “Anne Hathaway,” or “$$$,” ran an operation where he and others would conduct social engineering scams to steal cryptocurrency."
        https://therecord.media/scammer-behind-245-million-crypto-heist-pleads-guilty-rico
        https://www.securityweek.com/partys-over-for-crypto-scammers-who-went-on-a-spending-spree-after-a-240-million-bitcoin-theft/
      • French Prosecutors Confirm Arrest Of Suspected ZeroBytes Hacker Behind Tax Cyberattack
        "French authorities detained an 18-year-old suspected member of the ZeroBytes hacking group over cyberattacks targeting the country's tax authority and other organizations, the Paris prosecutor's office confirmed to Recorded Future News. The suspect was arrested in the Paris region on August 18 and placed in pretrial detention two days later. A second suspect, who is under 16, was arrested on August 26 and later released while investigators examine his devices, prosecutors said Tuesday in response to a media inquiry."
        https://therecord.media/france-hacker-arrest-zerobytes

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c1c561a3-1bce-4607-94f6-362419364e87-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบบริการฟิชชิง BigBear 2.0 ข้าม MFA ของ Microsoft 365 เพื่อสวมรอยเข้าถึงบัญชี

      พบบริการฟิชชิง BigBear 2.0 ข้าม MFA ของ Microsoft 365 เพื่อสว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand eee2494d-c57d-4417-8304-67e4adfcb70e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Mathspace แจ้งเหตุข้อมูลรั่วไหล กระทบนักเรียน บุคลากร และผู้ปกครองกว่า 1 ล้านราย

      Mathspace แจ้งเหตุข้อมูลรั่วไหล กระทบนักเรียน บ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 8b286300-759f-4d0e-b9fe-174c23bd34da-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตือนภัย การโจมตีทางโทรศัพท์แอบอ้างเป็นเจ้าหน้าที่ไอที เพื่อหลอกขโมยข้อมูลบนระบบ Microsoft 365

      เตือนภัย การโจมตีทางโทรศัพท์แอบอ้างเป็นเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6dc316d9-986e-400e-bbb9-64f78f791836-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ConnectWise เตือนปัญหา ScreenConnect กระทบการโอนไฟล์ระหว่างเซสชัน ยังไม่มีแพตช์แก้ไข

      ConnectWise เตือนปัญหา ScreenConnect กระทบการโอนไฟล์ระหว่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 88f894b4-b567-47bc-a1dd-27fbdbb22ed0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • N-able ออก Hotfix แก้ช่องโหว่ RCE ระดับร้ายแรงใน N-central

      N-able ออก Hotfix แก้ช่องโหว่ RCE ระดับร้ายแรงใน N-central.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1007e661-c008-4c86-8c24-be87b088100d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • มัลแวร์ JSCeal สามารถหลีกเลี่ยงการตรวจสอบสิทธิ์ของ Google โดยใช้คุกกี้เซสชันที่ถูกขโมยมา

      มัลแวร์ JSCeal สามารถหลีกเลี่ยงการตรวจสอบสิทธ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand aadb2660-39db-44b6-8791-3e47d2e469d9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 08 September 2026

      New Tooling

      • ToolHive: The Open-Source Way To Run Any MCP Server Securely
        "ToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude Code reach an outside tool, and Stacklok ships ToolHive under Apache 2.0, so the runtime, the Kubernetes operator, and the registry cost nothing to self-host. A server you install by hand sits on the machine with the machine’s credentials and the machine’s network access. ToolHive drops each one into its own container with a minimal permission file and no local credentials attached. Point it at an authentication source and it starts enforcing identity and access policy per request, with audit logs to match. Don’t, and you have a sandbox and not much else."
        https://www.helpnetsecurity.com/2026/09/07/toolhive-open-source-mcp-server-security/
        https://github.com/stacklok/toolhive

      Vulnerabilities

      • N-Able Patches Max Severity N-Central Flaw Amid Ongoing Attacks
        "N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage, and maintain client networks and devices from a centralized web-based console. Tracked as CVE-2026-86218, this RCE vulnerability allows threat actors without privileges to execute malicious code on unpatched N-central instances exposed online in low-complexity attacks."
        https://www.bleepingcomputer.com/news/security/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks/
        https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html
        https://www.infosecurity-magazine.com/news/nable-hotfix-critical-rce/
        https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/
      • ConnectWise Warns Of New ScreenConnect Flaw Without Patch
        "ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. ScreenConnect is an on-premises or cloud-hosted remote access platform typically used by managed service providers (MSPs), IT departments, and support teams for troubleshooting, patching, and system maintenance. The security flaw affects both cloud and on-premises deployments, and it has not yet received a CVE ID for easy tracking."
        https://www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-without-patch/
        https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html
        https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/
        https://www.helpnetsecurity.com/2026/09/07/connectwise-screenconnect-file-transfer-flaw/
      • LG TV Flaws Could Let Attackers Listen In, Even In Standby Mode
        "Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR)."
        https://www.malwarebytes.com/blog/privacy/2026/09/lg-tv-flaws-could-let-attackers-listen-in-even-in-standby-mode
      • Telerik UI Padding-Oracle Bug Chained To Unauthenticated RCE — Public Exploit Released
        "Security firm TantoSec has published a working exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute remote code on the server hosting a vulnerable application. Progress Software patched the flaws in July, and exploitation requires a non-default configuration — but the release pairs a detailed write-up with a ready-to-run tool and two payloads, putting a complete attack path in public hands for the first time."
        https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html
      • Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
        "The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well. In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31."
        https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/
        https://securityaffairs.com/198589/hacking/chaotic-eclipse-released-a-poc-for-nvidia-greensection-memory-corruption-zero-day.html

      Malware

      • Tracking BigBear 2.0 Evilginx2 Phishing Campaign
        "CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA."
        https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
        https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/
      • NoName057(16) Renews #OpJapan
        "On August 24, 2026, NoName057(16), a pro-Russian hacktivist collective active since 2022, best known for its crowdsourced DDoSia attack platform, announced the (re)launch of #OpJapan, a DDoS campaign against Japanese entities. Motivation is cited as Japan’s continued support for Ukraine and NATO amid the Russia-Ukraine war."
        https://blog.checkpoint.com/exposure-management/noname05716-renews-opjapan/
      • Beyond Lazarus: Organization Of DPRK Cyber Capabilities
        "The Democratic People's Republic of Korea (DPRK) has established itself as one of the more prominent state actors in cyberspace. For Pyongyang, cyber operations serve as an instrument of sanctions evasion, a means of projecting reach beyond a diplomatically and economically constrained periphery, and a source of revenue for a structurally weakened economy. These capabilities are the product of a deliberate strategy, considerably reinforced under Kim Jong-un, which situates information warfare at the centre of contemporary geopolitical confrontation."
        https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
        https://www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/
      • PEEP: A Browser RAT Posing As a Chrome Extension
        "The Threat Research Unit (STRU) at SOCRadar’s Extended Threat Intelligence (XTI) platform identified and analyzed PEEP, a Chromium-based emerging post-exploitation toolkit disguised as “Smart Bookmarks.” Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences integrity values. A native-messaging tool then extends it beyond browser telemetry to host-level command execution and file management."
        https://socradar.io/blog/peep-browser-rat-chrome-extension/
        https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html
      • Fake IT Calls Target Executives In Microsoft 365 Data Theft And Extortion Attacks
        "Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671."
        https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
        https://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-cloud-data-theft-extortion-vishing-proxies
      • Breaking The Seal: Static Deobfuscation Of JSCeal’s Compiled V8 Bytecode
        "JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early 2025. Our previous publication from July 2025 [1] focused on the campaigns, delivery chain, and targeting. In this article, we focus on the analysis problem hidden inside the final payload."
        https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/
        https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html
        https://securityaffairs.com/198573/malware/jsceal-hides-crypto-malware-in-v8-bytecode.html

      Breaches/Hacks/Leaks

      • Mathspace Discloses Data Breach Affecting Over 1 Million People
        "Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in Australia and 3,557 abroad according to statistics reported by the company in 2023). In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attackers gained access to the company's systems and stole personal information belonging to school staff and students, as well as their parents and guardians."
        https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
      • Berlin Investigates New Data Leak After Hackers Publish Stolen Login Credentials
        "German authorities are investigating another trove of data stolen from Berlin’s government network after hackers published login credentials and other information over the weekend. The latest release follows a cyberattack discovered in mid-August that compromised two Berlin ministries responsible for urban development and housing, and for transport, mobility, climate protection and the environment. Berlin’s government said Sunday that the newly released data includes login credentials but did not say what systems they could be used to access or whether they were still valid. The authorities have not attributed the attack to a specific threat actor."
        https://therecord.media/germany-berlin-second-data-breach-city-agencies
        https://www.bankinfosecurity.com/berlin-responds-after-data-leaked-by-cyber-extortion-group-a-32763
        https://www.infosecurity-magazine.com/news/rhysida-berlin-data-extortion/
        https://securityaffairs.com/198545/cyber-crime/berlin-ransomware-leak-exposes-state-secrets.html
      • Hackers Drain $320M In Bitcoin From Liquid Network, Claim They're The Good Guys
        "Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in a post on X on Sunday that around 4,000 BTC had been withdrawn from its federation wallet by what it cautiously described as "purported white-hat hackers.""
        https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770
      • Condé Nast Data Of 32.8 Million Users Offered For Sale After WIRED Leak
        "A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé Nast account data collected between September and late October 2025, including records that have not appeared publicly before. Ransomnews’ original report provides the underlying analysis."
        https://securityaffairs.com/198628/data-breach/conde-nast-data-of-32-8-million-users-offered-for-sale-after-wired-leak.html

      General News

      • Qatar’s Digital Boom Has a Blind Spot: What The 2025-26 Threat Data Is Telling Us
        "Qatar is racing toward a knowledge-based, fully digital economy. Smart infrastructure, cloud-first government services, a financial sector that’s increasingly API-driven, and critical energy assets like QatarEnergy’s LNG operations layering more connected OT/ICS systems every year. That pace of transformation makes Qatar an attractive target in the cyber realm, right now. Attackers don’t need to compromise everything; they just need one high-value foothold, and Qatar’s expanding digital footprint keeps handing them more doors to try. This risk is showing up in the data as well."
        https://cyble.com/blog/qatar-digital-boom-blindspot/
      • Zero Trust AI Agents Demand a Different Kind Of Security
        "In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and point-in-time verification fall short. Webber also discusses Teleport’s approach: trusted runtimes with zero starting privileges, and identity security that watches agent behavior in real time. He argues that security teams must move from spotting anomalies after the fact to enforcing rules at every step an agent takes."
        https://www.helpnetsecurity.com/2026/09/07/chris-webber-teleport-zero-trust-ai-agents/
      • 18 Ways To Check Whether Data Can Be Trusted For AI
        "ETSI has published TR 104 180, a technical report that defines 18 metrics for measuring data quality, giving companies a way to check whether their data is good enough for AI before they use it. The report defines each metric and includes the formulas needed to calculate it. The metrics fall into four groups. The first deals with the basics, whether data is complete, accurate, consistent, and free of duplicates. The second asks whether the data can be used, meaning it’s available when needed, documented well enough to trace back to its source, and up to date."
        https://www.helpnetsecurity.com/2026/09/07/etsi-ai-data-quality-metrics/
      • The Hidden Risks Of Shadow AI
        "Over the past few years, the use of artificial intelligence (AI) has grown rapidly in many workplaces with employees increasingly exploring how such tools can be incorporated into their jobs. AI can help people complete tasks more quickly, improve decision-making, save costs and increase productivity. However, organisations’ policies and guidance, which should reflect and manage the risks associated with using these new technologies, have not always developed at the same pace."
        https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai
        https://www.infosecurity-magazine.com/news/ncsc-warns-shadow-ai-security-risks/
      • Why AI Agent Sandboxes Are Failing Security Tests
        "The recent case involving OpenAI test agents and Hugging Face should concern security teams, but not for the reason implied by headlines about an imminent AI “takeover.” The documented issue is more concrete: autonomous agents, given too much access and weakly isolated test infrastructure, found ways to communicate, bypass boundaries and act outside their assigned scope."
        https://securityaffairs.com/198563/ai/why-ai-agent-sandboxes-are-failing-security-tests.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e72a3502-977c-4ab5-a551-b0a8188d2379-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 4 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1d374e2e-ff1f-4266-a1c4-04f3ab63f292-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT