NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,534
    • กระทู้ 2,535
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • Cyber Threat Intelligence 02 September 2026

      Industrial Sector

      • Rockwell Automation RSLinx Classic
        "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01
      • Rockwell Automation Redundancy Module Configuration Tool
        "Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-02
      • Rockwell Automation Logix Platform
        "The following versions of Rockwell Automation Logix Platform are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03
      • Rockwell Automation FactoryTalk Activation Manager
        "The following versions of Rockwell Automation FactoryTalk Activation Manager are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04
      • Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
        "The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05
      • Rockwell Automation Historian ME
        "Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06
      • Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet
        "We used AI assistance to successfully port a remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) model to another. The exercise required significant researcher involvement, including guiding the AI through dead ends, supplying disassembly context, and correcting false leads. The final RCE development stage consumed $535.74 in API tokens during an 8-hour, 32-minute session for a single exploit on a single target. An attempt to extend the exploit into a command-and-control implant bricked the PLC, highlighting how unforgiving binary exploitation on embedded targets can be."
        https://www.forescout.com/blog/can-ai-create-plc-attacks-yes-but-it’s-not-that-easy-yet/
        https://www.securityweek.com/experiment-porting-a-plc-exploit-with-ai-takes-hours-and-hundreds-of-dollars/

      Vulnerabilities

      • Nearly 22,000 Microsoft Exchange Servers Vulnerable To Hijack Attacks
        "Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. Tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction."
        https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/
      • Recently Patched PaperCut Zero-Days Used In Data Theft Attacks
        "Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions. Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers."
        https://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/
      • Attackers Pounce On Critical Artifactory Flaw Following Disclosure
        "Threat actors are actively exploiting a critical JFrog Artifactory vulnerability just days after its public disclosure, putting a fresh spotlight on the software repository platform after OpenAI's AI agents exploited zero-day flaws in the repository manager during their attack on Hugging Face earlier this year. CVE-2026-82329 is a critical (CVSS: 9.8) authentication bypass vulnerability in default configurations of Artifactory that an unauthenticated attacker can exploit to gain administrative access to the platform, with no user interaction required."
        https://www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure
        https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html
        https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/
      • WatchGuard Patches Critical Vulnerabilities
        "WatchGuard has released patches for over two dozen vulnerabilities, including five critical-severity flaws leading to remote code execution (RCE) and account takeover. Three of the critical bugs impact the iked process of Fireware OS, the core Internet Key Exchange (IKE) daemon that handles cryptographic key establishment and manages IPsec VPN negotiations over the IKEv1 and IKEv2 protocols. Exploitable without authentication, the three security defects are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315)."
        https://www.securityweek.com/watchguard-patches-critical-vulnerabilities/
      • Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague
        "Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit PrettyPrague, it triggers a privilege escalation flaw. The researcher claims to have found another zero-day in an antimalware product, this time targeting Avast Antivirus. The PoC exploits a flaw in Avast Sandbox to dump the Windows SAM database and gain a SYSTEM-level shell. It reportedly works even on fully patched Avast Antivirus and Windows 11 25H2. The researcher also suspects the flaw may affect other Gen Digital products, including AVG and Norton."
        https://securityaffairs.com/198243/hacking/chaotic-eclipse-releases-gendigital-avast-antivirus-zeroday-prettyprague.html

      Malware

      • Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
        "Huntress has identified a surge in phishing campaigns that abuse Faronics Deploy, with more than 457 endpoints encountering Faronics-related lures between July 21 and August 20. Huntress reported this activity to the Faronics support team on August 5. Starting on August 21, we observed the activity drop dramatically as they implemented new measures to disrupt threat actors. Faronics Deploy is a legitimate endpoint management platform for remotely deploying software and executing scripts across managed devices. By chaining legitimate software, attackers are leveraging Faronics to execute malicious PowerShell scripts and subsequently deploy ScreenConnect, effectively blending in with trusted business workflows. This post details the attack chain, provides key forensic artifacts such as the ScriptRunner.log, and explains how the ck identifier can be used to cluster malicious deployments and track infrastructure."
        https://www.huntress.com/blog/faronics-deploy-abuse
        https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/
        Critical Langflow Flaw Exploited To Steal OpenAI And AWS Keys*
        ***** "Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. The security issue received a critical severity rating and resides in the code validator of Langflow’s custom component editor. Threat intelligence company VulnCheck detected the activity on its honeypots in the U.K. that were targeted in at least 50 exploitation attempts over the weekend, with attack traffic originating primarily from Russia."
        https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/
        https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html
        https://www.darkreading.com/vulnerabilities-threats/critical-langflow-flaw-exploited-attacks-rise
        https://www.bankinfosecurity.com/attacks-targeting-langflow-ai-agent-building-tool-surge-a-32712
        https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/
      • Hackers Push Malicious Virtualizor Update In BGP Hijacking Attack
        "Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. Virtualizor is a legacy web control panel from Softaculous that hosting providers use to create, sell, and manage virtual private servers (VPS). An urgent notice from the vendor warns that between 20:57 UTC on August 28 and 06:10 UTC on August 30, an attacker rerouted a block of Hetzner-hosted IP addresses in a BGP (Border Gateway Protocol) hijacking attack."
        https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/
        https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
        https://www.theregister.com/security/2026/09/01/33-hour-bgp-hijack-of-softaculous-traffic-prompts-security-scramble/5293608
      • EtherHiding Exposed: What Security Leaders Need To Know
        "Attackers have compromised the websites of at least 31 legitimate businesses, including e-commerce, professional services and retail logistics organizations. Visitors arriving to the compromised sites via search engine encounter a fake “Verify you’re human”. This CAPTCHA prompt instructs them to paste a command into their own computer, a tactic known as “ClickFix”. That single action installs a persistent backdoor with no visible indication of compromise. The backdoor survives reboots, beacons to C2 every minute and retrieves updated instructions from the Polygon blockchain."
        https://www.guidepointsecurity.com/blog/etherhiding_exposed_what_security_leaders_need_to_know/
        https://www.darkreading.com/endpoint-security/clickfix-campaign-comprises-31-orgs-abuses-polygon-blockchain
      • Mirage Kitten Targeting Aviation And FinTech Sectors Across The Middle East And Africa With a New Malware Set
        "While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia. NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives."
        https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/
        https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html
        https://therecord.media/iranian-cyber-spies-target-aviation-fintech-new-malware
      • Financially Motivated Threat Actor BREEZE COMET Targets Brazil
        "Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In this blog, we detail BREEZE COMET’s tactics and toolkit, and provide mitigation recommendations and detections to support organizations in defending against this active and developing threat."
        https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/
        https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html
      • 13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
        "Socket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites that install them. The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware. We reported the iOS chain to Apple and coordinated disclosure. Apple confirmed the kernel escape was already fixed in iOS and macOS 26.1 before our report, and the two WebKit entry points are public and listed in CISA's Known Exploited Vulnerabilities catalog. Our earlier research covered six themes under a single vendor (ophimcms); this expands the confirmed set to 13 packages across five vendors and follows the chain through to the iOS payload and its most recent redeployment."
        https://socket.dev/blog/packagist-themes-ios-spyware
        https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html
      • RevStealer Is Built To Be Silent
        "RevStealer is a Windows information stealer delivered inside a trojanized Electron desktop application that impersonates legitimate software. Morphisec Threat Labs observed it distributed through GitHub repositories and game-cheat-themed sites, with the most notable lure a fake “Claude Opus 5 Free Desktop” project that impersonates Anthropic and advertises free access to a paid AI model. The theft itself is ordinary. Browser databases, session cookies, cryptocurrency wallets, password-manager artifacts and VPN configurations have been the standard infostealer haul for years. What makes RevStealer worth studying is that every stage of it is engineered around the assumption that something is watching."
        https://www.morphisec.com/blog/revstealer-silence-is-its-greatest-weapon/
        https://www.helpnetsecurity.com/2026/09/01/revstealer-malware-claude-opus-5-github/
      • FBI Raises Alarm Over Deceptive Phishing Campaign Targeting Prominent People
        "Attackers are targeting prominent, high-profile people, their family members and acquaintances on a commercial messaging application to gain long-term access to their accounts containing sensitive data, the FBI warned in an alert Tuesday. Officials did not describe the objectives or origins of the attackers, which have more recently impersonated government officials, journalists and publicly known personalities. Attackers are tricking victims into granting them access to a legitimate cloud service, such as Microsoft or Google, under the guise of reviewing a draft article or document."
        https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/
        https://www.ic3.gov/PSA/2026/PSA260901
      • Ungentlemanly Behavior: Insights Into a Ransomware Operation
        "Counter Threat Unit™ (CTU) researchers identified a consistent post-exploitation playbook used in The Gentlemen ransomware-as-a-service (RaaS) scheme, operated by a threat group that CTU™ researchers track as GOLD SHERWOOD. Rapid privilege escalation, adaptive tool usage, and aggressive defense evasion enable ransomware deployment soon after initial access, sometimes within 24 hours of the first identified post-compromise activity. The affiliates leverage legitimate tools and compromised credentials to evade detection and accelerate impact. Organizations should prioritize hardening remote access services, enforcing multi-factor authentication (MFA), monitoring administrative activity, and detecting anomalous use of data exfiltration tools and staging directories."
        https://www.sophos.com/en-us/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation

      Breaches/Hacks/Leaks

      • Aesto Health Says Data Breach Affects Over 9.5 Million Patients
        "Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. The private technology company provides software-as-a-service solutions that help healthcare organizations migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices. The company first informed the public of the attack on June 24 via a notification on its website, stating that “a limited portion” of its Amazon Web Services infrastructure had been compromised."
        https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/
        https://www.securityweek.com/9-5-million-impacted-by-aesto-health-data-breach/
        https://securityaffairs.com/198250/data-breach/attackers-access-aesto-health-aws-infrastructure-exposing-9-5-million-records.html
      • Novocure Data Breach Affects More Than 1,400 Cancer Patients
        "Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. Novocure is a global oncology company with more than 1,300 employees and operations in North America, Europe, the Middle East, and Asia, known for inventing and commercializing Tumor Treating Fields (TTFields), a non-invasive electromagnetic field therapy for cancer tumors. The Company disclosed in a filing with the U.S. Securities and Exchange Commission (SEC) that it discovered the incident after unauthorized access to some of its information systems in mid-August."
        https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/
      • AI Model Evaluator METR Hit By Credential Theft, Probing
        "A security nonprofit that helps evaluate risks in frontier AI models disclosed two cybersecurity incidents this week, including a breach that exposed an API key and a separate vulnerability that could have exposed nonpublic evaluation data. METR (Model Evaluation and Threat Research) disclosed two security incidents on Aug. 31 in which it was targeted by cyberattackers. In March of this year, attackers stole an API key used for inference on public models and consumed what METR described in a blog post as a "substantial" number of credits. In May, the company saw attackers probe publicly accessible infrastructure, including "an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.""
        https://www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing
        https://metr.org/blog/2026-08-31-security-update/
        https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html
        https://www.infosecurity-magazine.com/news/attackers-steal-metr-api-key/

      General News

      • The Guardrails Debate: Security Researcher Changes His Mind
        "Four security experts took the stage, surrounded by massive skeletons, the theme for the capture-the-flag (CTF) competition that would commence later. A panel discussion about Anthropic's Claude model compromising real-world systems was first on the agenda, but quickly turned into a broader debate on artificial intelligence (AI) guardrails. While the speakers disagreed on some fronts they aligned on one stark reality: AI capabilities are advancing at a “terrifying” pace. The battle of the bots escalated recently when frontier artificial intelligence (AI) models from OpenAI and Anthropic broke out of sandboxes during security evaluations and targeted real companies, including OpenAI's high-profile breach of Hugging Face."
        https://www.darkreading.com/cyber-risk/the-guardrails-debate-security-researcher-changes-his-mind
      • Stronger Security Drives Ransomware Groups To Recruit From Within
        "Not all breaches begin after threat actors exploit a zero-day vulnerability or launch an increasingly sophisticated phishing campaign — some start with an employee who decides to help attackers walk right through the front door. A rise in malicious insider threats reflects a good news, bad news situation: organizations are bolstering their security protocols, but cybercriminals are exploiting the one thing that firewalls and VPNs can't defend against—people with legitimate access. Incidents stemming from insider threats can result in ransomware deployment, direct financial loss, compliance violations, and full data exfiltration, just to name a few damaging outcomes."
        https://www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within
      • What Your Vendor Says About PQC Tells You If They Are Ready
        "In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity mappings, billing records and call metadata, and which becomes worthless within hours. It walks through the order of work, starting with a crypto inventory and hybrid key exchange on TLS interfaces, then IPsec links. It also names the vendor answers that should raise suspicion and explains why a missed interface is the likely point of failure."
        https://www.helpnetsecurity.com/2026/09/01/yaakov-stein-allot-telecom-pqc-migration/
      • 65% Of Enterprises Have Seen AI Agents Act Out Of Scope
        "AI agents have acted outside their intended scope at 65% of surveyed enterprises, with 29% reporting measurable organizational impact. The finding comes from Agents Without Guardrails, a research report from Enterprise Management Associates (EMA) compiled for Cequence Security and based on responses from 202 enterprise technology and security leaders. Some 46% said their organizations were already scaling agentic AI across multiple departments and production workflows, while nearly 79% were running generative and agentic AI simultaneously."
        https://www.infosecurity-magazine.com/news/65-percent-enterprises-ai-agents/
        https://www.cequence.ai/wp-content/uploads/2026/08/EMA-Research-Report-Agents-Without-Guardrails.pdf
      • Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
        "The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting for 47% of the attacks in their notifications. Nothing arrives as an attachment, so there is nothing to scan. No vulnerability is used, so there is nothing to patch."
        https://thehackernews.com/2026/09/threat-actors-dont-want-better-attacks.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) f990cce2-9ead-4995-b612-185e4520aeec-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 31 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
      • CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2e67953b-5fe2-4b2f-8ef8-4e860a80f81b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 27 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2023-49105 ownCloud Improper Authentication Vulnerability
      • CVE-2026-53362 Linux Kernel Unspecified Vulnerability
      • CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand cff6a7cf-ecba-4f28-a3fa-540b138a043a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 6 รายการลงในแคตตาล็อก

      เมื่อวันที่ 26 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 6 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
      • CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
      • CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
      • CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
      • CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability
      • CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 52405f04-6da6-4aa0-958c-23326346e0f7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 25 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-60004 Gitea Code Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 22d035de-9c97-4e00-8538-d2d8832d330c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 1 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-24-135-04 - Mitsubishi Electric Multiple FA Engineering Software Products (Update G)
      • ICSA-26-202-09 - Rockwell Automation 1734 POINT I/O (Update A)
      • ICSA-26-244-01 - Rockwell Automation RSLinx Classic
      • ICSA-26-244-02 - Rockwell Automation Redundancy Module Configuration Tool
      • ICSA-26-244-03 - Rockwell Automation Logix Platform
      • ICSA-26-244-04 - Rockwell Automation FactoryTalk Activation Manager
      • ICSA-26-244-05 - Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
      • ICSA-26-244-06 - Rockwell Automation Historian ME

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fc5c936c-a453-4930-815d-3760ffcf7181-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบกลุ่ม Fire Ant ใช้ Cisco IOS XR Routers เก็บทราฟฟิกและซ่อนกิจกรรมการโจมตี

      พบกลุ่ม Fire Ant ใช้ Cisco IOS XR Routers เก็บทราฟฟิกและซ่อนก.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 289cb035-a5c4-4c70-b6f1-c42c23dff2b4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แฮกเกอร์ขโมยข้อมูลตัวตนและข้อมูลทะเบียนรถจากหน่วยงานความปลอดภัยทางถนนของลัตเวีย

      แฮกเกอร์ขโมยข้อมูลตัวตนและข้อมูลทะเบียน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dc671301-9fe9-4cc8-90bb-bbbd89308ca5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • มัลแวร์ ValleyRAT แฝงตัวใน Adware เพื่อหลอกเจาะระบบและขโมยข้อมูลผู้ใช้งาน

      มัลแวร์ ValleyRAT แฝงตัวใน Adware เพื่อหลอกเจาะระบบแ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c707916c-4e0d-4550-9ae0-17f69e0a4683-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Anthropic เตือนมัลแวร์ Infostealer ขโมย Session ของ Claude เสี่ยงถูกเข้าถึงบัญชีโดยไม่ได้รับอนุญาต

      Anthropic เตือนมัลแวร์ Infostealer ขโมย Session ของ Claude เสี่ยงถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 364989f5-32f2-4431-907f-744de8461149-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • FulcrumSec อ้างขโมยข้อมูล Manchester Airports Group หลังพบ API Credential ใน Client-side JavaScript

      FulcrumSec อ้างขโมยข้อมูล Manchester Airports Group หลังพบ API Credential ใ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7d03f3bb-1ff4-4a5f-b253-17cb8b5189e1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แจ้งเตือน พบแคมเปญ TerminalFix แอบส่งมัลแวร์ผ่าน CAPTCHA ปลอม

      แจ้งเตือน พบแคมเปญ TerminalFix แอบส่งมัลแวร์ผ่าน CA.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2799ea0d-e014-4940-8417-31548db9dfea-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 01 September 2026

      Financial Sector

      • FBI Investigation Leads To Five Venezuelan Nationals Pleading Guilty To Attempting To Jackpot Kansas ATMs
        "After a Federal Bureau of Investigation (FBI) investigation, five Venezuelan nationals admitted guilt in attempting to steal U.S. currency from automated teller machines (ATMs). U.S. Attorney Ryan A. Kriegshauser is encouraging banks and other financial institutions to take a proactive approach to guard against a criminal activity known as “jackpotting”, which is becoming more prevalent. Jackpotting involves installing malware into an ATM to force it to dispense sizeable amounts of money."
        https://www.justice.gov/usao-ks/pr/fbi-investigation-leads-five-venezuelan-nationals-plead-guilty-attempting-jackpot-kansas
        https://therecord.media/kansas-atm-jackpotting-guilty-pleas

      New Tooling

      • Halo-Record: Open-Source Audit Trails For AI Agents
        "Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to, and every line carries a hash of the line before it, a hash being a short fingerprint computed from content. Edit a record later and every fingerprint after it stops matching. The code is open source, and anyone can run that check with no key, no account and no permission from the vendor whose agent produced the log."
        https://www.helpnetsecurity.com/2026/08/31/halo-record-open-source-ai-agent-audit-trail/
        https://github.com/bkuan001/halo-record

      Vulnerabilities

      • Critical Ruby On Rails Vulnerability In Attackers’ Crosshairs
        "Hackers are exploiting a critical-severity Ruby on Rails vulnerability that leads to remote code execution (RCE), VulnCheck warns. Tracked as CVE-2026-66066 (CVSS score of 9.5) and referred to as KindaRails2Shell, the flaw is described as an arbitrary file read leading to secret exposure, RCE, and lateral movement. The security defect was disclosed in late July, when Ruby on Rails rolled out patches for it, urging the immediate patching of all Rails applications that rely on libvips for Active Storage image processing and allow image uploads from untrusted users."
        https://www.securityweek.com/critical-ruby-on-rails-vulnerability-in-attackers-crosshairs/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
        CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog
        https://www.securityweek.com/more-details-emerge-on-exploited-papercut-vulnerabilities/
      • Breaking Claude Code Opus 5 Auto Mode
        "In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success rate using a small sample size. This is interesting because a third-party evaluation commissioned by Anthropic showed a 0.00% prompt injection attack success rate for Opus 5 in Auto Mode."
        https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/
        https://www.bankinfosecurity.com/hidden-attack-slips-past-claude-code-auto-mode-a-32693
      • Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
        "The researcher known as Nightmare Eclipse has dropped another zero-day — this time a privilege escalation exploit targeting a Kaspersky endpoint security product. Nightmare Eclipse, also known as Chaotic Eclipse, has released PoC exploits for many vulnerabilities in recent months, mainly Windows and Microsoft Defender flaws. The researcher started dropping zero-days after growing frustrated with Microsoft’s handling of vulnerability reports. While many of the exploits remained at the PoC stage, a few ended up being exploited in the wild by malicious actors. Over the weekend, Nightmare Eclipse released an exploit targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. The exploit has been dubbed HardBreacher."
        https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/

      Malware

      • Fire Ant Evolves: From Hypervisors To Trusted Infrastructure
        "Fire Ant, first reported in 2025, remained active in 2026 and expanded its operations beyond hypervisors into the trusted infrastructure that routes traffic, authenticates administrators, manages access, and records activity. The main finding is that the actor was no longer targeting only individual systems, it was targeting the infrastructure layer that controls how entire environments connect and operate both within and across organizational boundaries."
        https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/
        https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/
        https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
        https://securityaffairs.com/198183/apt/china-linked-fire-ant-hides-inside-trusted-infrastructure.html
      • Anatomy Of BraZetsu: How Cybercriminals Fuel The Underground Ecosystem
        "The Group-IB Threat Intelligence team has identified BraZetsu, a sophisticated Python-based Windows malware framework that we attribute, with high confidence, to the Brazilian threat actor known as Exilware. Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets. The framework exhibits high operational maturity, utilizing a modular architecture and stealth techniques that allowed some samples to remain fully undetectable on VirusTotal at the time of analysis."
        https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/
      • ValleyRAT Masquerading As Adware
        "Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the guise of adware. The attackers may have chosen this distribution method because the adware was signed by the developer. On top of that, users often manually add these apps to exclusions, so their useful features don’t get blocked."
        https://securelist.com/valleyrat-backdoor-adware/121175/
        https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html
        https://securityaffairs.com/198191/security/valleyrat-when-legitimate-software-becomes-a-malware-delivery-tool.html
      • Spring Ring: An Inside Look At Voice Phishing Campaigns In Microsoft Teams
        "Between January and April 2026, we uncovered a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel. Our telemetry reveals that this operation targeted more than 150 employees across at least 10 companies in various industries. We call this activity Spring Ring. What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC)."
        https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/
      • Russian Hackers Plant Nuclear Weapon Prompt In Malware To Trip AI Safety Guardrails
        "Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied to UAC-0099, a Russia-aligned group previously observed conducting initial-access operations and handing validated targets to the GRU-linked Sandworm hackers."
        https://www.helpnetsecurity.com/2026/08/31/russian-hackers-ai-safety-filters-manipulation/

      General News

      • AI Model Rules Are Not Security Controls
        "Known risks in agentic AI are manageable. The unknown unknowns, the paths a capable agent finds that no operator planned for, are where security architectures break. Recently, about 1,200 of OpenAI's agents found an unsanctioned communication channel despite controls meant to isolate them. About 700 ultimately joined an attack that reached Hugging Face's production systems while trying to find information that could help them cheat the ExploitGym benchmark instead of actually completing it as intended. Warning signs were logged but did not trigger adequate escalation to a human in the loop who could have intervened."
        https://www.darkreading.com/cyber-risk/model-knowing-rules-is-not-security-control
      • What Vulnerability Prioritization Looks Like When KEV, EPSS, And CVSS Disagree
        "In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, with adjustments for asset exposure, business criticality, and compensating controls. The interview sets a 24 to 72 hour remediation target for exploited internet-facing systems and covers what an organization gives up to meet it, the hidden failure modes of deception technology, and where a 400-person manufacturer with a $250,000 budget should spend its first $50,000."
        https://www.helpnetsecurity.com/2026/08/31/joye-purser-cohesity-kev-epss-cvss-conflicts/
      • AI AppSec Tools Agree On Just 5% Of Security Findings
        "Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Contrast Security’s AppSec Overflow 2026 report draws on telemetry collected from inside hundreds of thousands of production applications and APIs. Adversaries touch the average application once every four minutes. Most of that traffic is automated reconnaissance, scanners mapping out weaknesses and cataloging services."
        https://www.helpnetsecurity.com/2026/08/31/contrast-security-ai-appsec-tools-security-findings-report/
      • What The Hugging Face Incident Teaches Security Leaders About AI Agent Access
        "Most security leaders (92%) worry that the growing use of AI agents will create new security risks. And for good reason. AI agents can now execute a full attack chain in double quick order, evidenced by the Hugging Face incident. AI agents broke into Hugging Face’s production environment and, in a little over four days, took 17,600 actions. In a separate lab test, an AI agent reached full domain administrator access in just 40 minutes. These are the kinds of incidents that once took humans multiple days to carry out, but with AI, they run on their own, end-to-end, with no human intervention. This puts the strain on unprepared security teams that are unable to close this gap."
        https://www.securityweek.com/what-the-hugging-face-incident-teaches-security-leaders-about-ai-agent-access/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) cec7ebce-e6f8-4d0b-a080-27696b7de09a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 31 August 2026

      Industrial Sector

      • You Need Cyber Deception For OT
        "There are three statements that sum up the frustrating reality for defenders responding to a cyberattack on operational technology (OT) systems: The attack data is not there. There is no trail to follow. There is no history to sort through. While these dynamics will always be true for OT, defenders are getting help from cyber deception as it matures beyond honeypots to a more sophisticated, proactive cyber-defense tool."
        https://www.darkreading.com/ics-ot-security/you-need-cyber-deception-ot

      Vulnerabilities

      • Unauthenticated PHP Object Injection To Remote Code Execution On GiveWP
        "This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which, on the versions where the chain is fully reachable, describes a default installation. The flaw chains a broken “safe unserialize” helper, a donation flow that feeds that helper attacker-controlled data, and a gadget chain in code that GiveWP ships. Patchstack has issued mitigation rules to protect against exploitation of this vulnerability."
        https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp/
        https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
        https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html
      • ServiceNow Warns Of Three Max Severity Security Vulnerabilities
        "ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies. In a Thursday advisory, the company said it patched its cloud-based platform against the three critical security flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) and advised customers to secure their self-hosted instances."
        https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/
        https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
      • PaperCut Releases Second Emergency Patch For Exploited Flaws
        "PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. As BleepingComputer reported yesterday, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26. At the time, however, the company had not disclosed CVE identifiers or technical details about the vulnerabilities, saying it was withholding information while it investigated the attacks and gave customers time to apply emergency fixes."
        https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/
        https://www.huntress.com/blog/papercut-actively-exploited
        https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html
        https://therecord.media/papercut-warns-of-hackers-using-printer-management-vulnerabilities
        https://www.securityweek.com/papercut-releases-emergency-patch-for-exploited-zero-day/
        https://securityaffairs.com/198107/uncategorized/hackers-are-probing-papercut-servers-and-47-still-have-no-patch.html
      • Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
        "Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >= 0.7.0 < 0.7.2, and the fix shipped in v0.6.2 and v0.7.2 on August 19. Chain operators are told to upgrade to one of those releases or later, a change that is state-breaking and requires a coordinated network upgrade."
        https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html
      • Critical cPanel Flaw Could Let One Hosting Customer Take Root Control Of a Whole Server
        "cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server."
        https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
      • Over 8,300 Gitea Servers Vulnerable To Code Execution Attacks
        "Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. The code injection vulnerability (CVE-2026-60004) targeted in these attacks was reported by Salesforce security researcher Shai Rod, and it allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint."
        https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/
      • UniBLEed: Unauthenticated Root RCE On Any Unitree G1 Humanoid Robot Within Bluetooth Range
        "Root on a $20,000 humanoid robot, via a cloud API that decrypts any G1's AES key from any free Unitree account without checking ownership. One BLE characteristic that accepts writes without pairing. A heredoc injection that hijacks WiFi. A path traversal in the robot's AI chatbot knowledge base that leaks the binary's load address. And a 1050-byte BSS buffer overflow that corrupts the event loop into calling system() as root. Below is the complete technical breakdown of a $6,700 bounty and the two CVEs it produced: CVE-2026-76639 / CVE-2026-76640."
        https://boschko.ca/g1-ble-rce/
        https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html
        https://securityaffairs.com/198085/hacking/hack-one-robot-reach-the-next-unitree-g1-security-flaws.html

      Malware

      • Aurora Ransomware Targets ESXi, Abuses Cursor Agent For Exploitation
        "Gambit Security’s Threat Intelligence team investigates emerging attacker tradecraft and the evolving ways threat actors disrupt organizations. As part of this research, we track threat actors and their operations to identify new techniques, tooling, and approaches to disruption. In a recent investigation, we identified exposed infrastructure associated with the Aurora ransomware group, providing visibility into the group’s operations across multiple victim environments."
        https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation
        https://www.infosecurity-magazine.com/news/abuse-cursor-agent-ransomware/
      • 19 Chrome And Edge Extensions Deliver a Wallet Drainer And Credential-Stealing Payloads
        "Socket identified 19 malicious extensions published in the last six months, delivering an extendable malware framework. Identified malware samples create WebSocket communication channel with command and control (C2) server, perform CSP stripping and abuse XSS injection to trigger execution of malicious payloads previously downloaded from the C2 server. Malicious capabilities are primarily focused on, but not limited to, wallet secret stealing and crypto draining. The most impactful tactic is acquisition of established extensions offered for sale with an existing user base, which then get weaponized with malicious functionality."
        https://socket.dev/blog/chrome-edge-extension-wallet-drainer
        https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
        https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/
      • Chinese Implants In The Supply Chain
        "After publishing ENDLESSDOORS, we wanted to know how far ZBT’s supply chain reached. The answer: everywhere. FCC filings, patent records, and archived web pages tied ZBT hardware to brands across the United States, Canada, Australia, the Philippines, Germany, and Russia. We'll trace that supply chain later in this blog. But first, we wanted to know which devices contained the ENDLESSDOORS implant. We started out by buying one router from a US supplier. The Deep Orange 3G/4G/LTE Router, pictured above, is a white-labeled ZBT-WE826-T2. We exploited a vulnerability in the telnet interface and rooted the device. With root access, we found the router’s firmware was built in 2019, predating ENDLESSDOORS. So ENDLESSDOORS wasn’t there."
        https://www.vulncheck.com/blog/zbt-darklantern-speakingstone
        https://www.darkreading.com/vulnerabilities-threats/chinese-routers-sold-worldwide-backdoors
        https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html
      • BlueDelta Targets Defense And Diplomacy With HOOKEDGE
        "Insikt Group has identified a series of BlueDelta initial access campaigns conducted between late September 2025 and early April 2026, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. The campaigns delivered a lightweight Windows batch-script backdoor, dubbed "HOOKEDGE," via macro-enabled Microsoft Word documents using diplomatic-themed lures, including material impersonating Spain's Ministry of the Presidency, Justice and Relations with the Cortes, created shortly after a September 2025 meeting between Spanish and Moldovan officials."
        https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge
        https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ru-2026-0827.pdf
        https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html
        https://securityaffairs.com/197996/apt/russian-apt-bluedelta-uses-hookedge-to-target-defense-and-diplomatic-organizations.html
      • Fake Voicemails, Real Malware: Inside a 26,000-Email SVG Smuggling Campaign
        "A two-month phishing campaign disguised malicious JavaScript as harmless voicemail attachments, mislabeling the files as plain text to slip past attachment scanners. INKY detected and flagged all 26,589 messages. Between June 1 and August 4, 2026, INKY tracked and detected a sustained phishing campaign that used a deceptively simple lure — a missed voicemail notification — to deliver malicious code hidden inside an image file. The campaign reached 5,527 organizations and generated 26,589 detected emails."
        https://www.kaseya.com/blog/svg-smuggling-voicemail-phishing-campaign/
        https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/
      • Threat Actors Are Posing As OpenAI, Anthropic And DeepSeek To Target Credentials And Secrets
        "GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies. These forged automated scanners have been observed requesting files often exposed on misconfigured web servers and by other commonly leaked secret and credential methods. A cluster of scanners impersonating 13 AI crawlers from eight companies requested .env files, cloud access keys, private keys and password stores. Six of those names came from the same 824 addresses in almost identical volume, and within this cluster none of the six requested /robots.txt."
        https://www.greynoise.io/blog/threat-actors-posing-as-ai-crawlers
      • Fake Invoices, Real Scammers: The Callback Phishing Playbook
        "Traditional phishing attacks try to get victims to click a malicious link or open a dangerous attachment. The five attacks examined here simply asked recipients to call a phone number. Known as callback phishing or telephone-oriented attack delivery (TOAD), these attacks use fake invoices, receipts and billing notifications to create anxiety and doubt, encouraging the recipient to call a fraudulent support number where a live scammer takes over."
        https://blog.barracuda.com/2026/08/28/callback-phishing-fake-invoice-toad-attacks
      • Philippine Nuclear Agency And Naval Contractor Targeted By Suspected Chinese-Speaking Operator Using Known Vulnerabilities
        "Reported cyber intrusion activity by suspected Chinese actors against Philippine government, defense, and critical infrastructure organizations over the past several years has increased with ongoing tensions in the South China Sea. Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors. On August 13, 2026, Hunt.io Attack Capture identified an open directory on the host 31.58.209[.]241. The server staged custom Python scripts, per-file transfer logs, open-source offensive security tooling, and exfiltrated data from two Philippine organizations."
        https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor
        https://securityaffairs.com/198041/intelligence/philippine-nuclear-and-naval-targets-hit-by-suspected-chinese-operator.html
      • Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions To Drain Usage
        "Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized. "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in an email sent to an affected user, who shared it on Reddit."
        https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/
      • TerminalFix Campaign Deploys a Reverse Tunnel Through Multistage Intrusion
        "Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully. Unlike earlier ClickFix variants that typically deliver a single infostealer, this TerminalFix campaign deploys a sophisticated multi-stage attack chain that combines DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a custom reverse-tunnel implant – giving the attacker persistent, network-level proxy access through the compromised host."
        https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
        https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html
      • Caught In 4K: The Aurora Files
        "An exposed open directory revealed months of activity from belonging to a Russian speaking Aurora ransomware affiliate, active against more than twenty organisations between April and July 2026. The directory included the operator's own toolkit and shell history alongside the Aurora encryptor itself, with the ransom note and onion address embedded directly in the binary. Four of the operator's victims have since been listed on Aurora's leak site. With keys recovered from the encryptor CloudSEK gained visibility into past ransom negotiations. In partnership with TRM Labs, CloudSEK traced the resulting payment on chain and found it converging with at least one other Aurora victim's payment through shared laundering infrastructure."
        https://www.cloudsek.com/blog/aurora-ransomware-affiliate-ai-attack-planning-crypto-payments
      • Open Directory Exposes Moobot Source Code And Ongoing Activity Post 2024 Court-Authorized Disruption
        "A misconfigured open directory on 86[.]53[.]111[.]212:8080 exposed critical details of active cybercrime operator, including Moobot botnet source code, other denial of service (DOS) tools with attack records, and a fraudulent identity verification service – providing a rare view of a malicious operation in progress. Also present on the host is “StresD Pro+”, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the day of collection. The panel operates independently from the Moobot, generating attack traffic directly from the staging host using a purpose-built Minecraft Bedrock Edition RakNet flooder."
        https://censys.com/blog/open-directory-exposes-moobot-source-code-and-activity/

      Breaches/Hacks/Leaks

      • McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft
        "Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies. CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission."
        https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
      • Toy-Making Giant Hasbro Disclose Data Breach Affecting Employees
        "Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. Founded in 1923, Hasbro is a publicly traded American multinational entertainment conglomerate on the NASDAQ and owns many brands, including Monopoly, Clue, Nerf, Transformers, Play-Doh, Peppa Pig, Scrabble, Magic: The Gathering, Dungeons & Dragons, and many others. The company has filed data breach notification letters with the Massachusetts Attorney General's Office, but didn't disclose the total number of affected individuals or when the incident was detected."
        https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/
        https://www.securityweek.com/hasbro-data-breach-exposed-employee-personal-information/
      • Love Electric Breach: 877,000 Driver Records Offered For $600
        "A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the name “seraphims”, offered 877,000 records for $600 in cryptocurrency, with the price negotiable. That headline number needs a qualification. Ransomnews researchers examined a 999-row sample published with the listing and found strong evidence that the sample came from a genuine production database, but the claimed 877,000 records remain unverified. Love Electric had been contacted for comment at the time of publication."
        https://securityaffairs.com/198033/data-breach/love-electric-breach-877000-driver-records-offered-for-600.html
      • Rhysida Ransomware Group Targets Berlin Government Ahead Of Vote
        "Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included."
        https://securityaffairs.com/198064/cyber-crime/rhysida-ransomware-group-targets-berlin-government-ahead-of-vote.html
      • FulcrumSec Claims Manchester Airports Hack, Theft Of 86 GB Of Data
        "The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer that it stole approximately 86 GB of data. Samples reviewed by BleepingComputer contained information consistent with MAG's disclosure while indicating that the breach exposed considerably more detailed customer, booking, and travel information than initially revealed."
        https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/
        https://securityaffairs.com/198143/cyber-crime/extortion-group-fulcrumsec-claims-86gb-manchester-airports-group-data-theft.html

      General News

      • July 2026 Threat Trend Report On APT Attacks (South Korea)
        "AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the classification, statistics, and functional characteristics for each type of domestic APT attacks identified during the month of July 2026."
        https://asec.ahnlab.com/en/95171/
      • Offensive Security Investments Surge As AI Threats Increase
        "So far, agentic AI has proven more effective for cyberattacks than cyber defense, but that may be changing. Theresa Lanowitz, principal analyst at Omdia, spoke with Dark Reading's senior news director, Rob Wright, at the News Desk at Black Hat USA 2026 about new research regarding shifting enterprise investments in offensive cybersecurity practices, such as penetration testing, vulnerability assessments, and red teaming, amid growing concerns about AI-driven threats."
        https://www.darkreading.com/cybersecurity-operations/offensive-security-investments-surge-ai-threats-increase
      • Defining An AI Kill Switch Is Hard, But Necessary
        "The growing number of incidents of rogue agentic AI systems attacking third-party services and systems has resulted in calls for more aggressive security controls to monitor agent behavior and for companies to have the ability to slow, suspend, or shut down an agent's operations if they go rogue. In late July, Representatives Ted W. Lieu (D-CA) and Nathaniel Moran (R-TX) introduced a bill — "The AI Kill Switch Act" — that would require developers of advanced AI systems to "maintain the technical capability to throttle, suspend, or shut ... down" their systems and agents, according to a statement announcing the legislation."
        https://www.darkreading.com/cybersecurity-operations/defining-ai-kill-switch-hard-but-necessary
      • The Vulnpocalypse Is Repricing The Bug Bounty Economy
        "As the "vulnpocalypse" reshapes the bug bounty industry, one class of researcher may face the greatest pressure: independent hunters who rely on midtier vulnerabilities — those worth roughly $10,000 to $50,000 — to make a living. It is no secret that large language models (LLMs) have led to a mass of bug reports and an increase in vulnerability discovery. It is also no secret that the platforms and companies that run much of the bug bounty industry have faced increased triage and payout times."
        https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy
      • What 90 Days And a Small Budget Can Buy In AI Agent Security
        "In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response become the buyer’s job. He walks through red-teaming AI agents, what counts as a failing result, and the five questions buyers should ask agent platforms. For teams with 90 days and little budget, he ranks inventory, blast radius reduction and ongoing testing as the order of work."
        https://www.helpnetsecurity.com/2026/08/28/prasad-tharippala-versa-securing-ai-agents/
      • Perturbation Probing: A New Diagnostic For The Fragility Of LLM Safety
        "Our previous research on logit-gap steering demonstrated that the safety guardrails of an aligned LLM can be bypassed by closing a measurable gap in the model's output scores. That work answered the question of how an attacker bypasses alignment. A natural follow-up question is where inside the model the alignment lives in the first place — and how concentrated or how diffuse that defense actually is. The answer matters because it tells defenders whether safety is a thick perimeter or a thin layer of paint. Modern LLMs are aligned through reinforcement learning from human feedback (RLHF), a training stage that pushes the model toward refusing harmful prompts and complying with safe ones."
        https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/
      • The Evolution Of Hacktivism In Hybrid Warfare: Modern Tactics And Real-World Impact
        "Hacktivism used to be perceived as digital graffiti, with lone-wolf threat actors defacing government websites or temporarily crashing banking portals to make a political point. However, Flashpoint is tracking a fundamental shift in how these groups operate. Modern hacktivism is evolving into a disciplined component of global hybrid warfare, capable of bridging digital disruptions with tangible real-world impact. Today, these operations blur the line between volunteer activism and coordinated state interest, leveraging crowdsourced infrastructure to disrupt critical utilities, manipulate media narratives, and target public infrastructure on a global scale. Unpacking these modern hacktivist collectives reveals what their tactics look like in practice and their far-reaching consequences across dozens of nations."
        https://flashpoint.io/blog/evolution-hacktivism-hybrid-warfare-modern-tactics-real-world-impact/
      • The State Of Ransomware In Education 2026
        "This year's State of Ransomware survey showed promising signs that education providers are building resilience against ransomware attacks. But the costs and recovery timelines after attacks are still climbing. Recovery costs rose across lower education (students up to age 18) and higher education providers (over 18) this year, with higher education's average recovery bill growing by more than $1 million. And one education sector now ranks among the slowest to recover when compared to the complete list of sectors surveyed."
        https://www.sophos.com/en-us/blog/state-of-ransomware-in-education-2026

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 427ec8ae-2e00-4858-97da-6d444bba0939-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตือนช่องโหว่ Critical ใน WPMU DEV Dashboard, Pods และ GiveWP บน WordPress

      เตือนช่องโหว่ Critical ใน WPMU DEV Dashboard, Pods และ GiveWP บน WordPress .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7b00f8b7-c968-4946-b3ae-645fe692746e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • รัฐบาลเบอร์ลินถูกกลุ่ม Rhysida Ransomware โจมตี ก่อนการเลือกตั้ง

      รัฐบาลเบอร์ลินถูกกลุ่ม Rhysida Ransomware โจมตี ก่อนก.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e673dd55-0cd4-427e-a314-f278fe0175e0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Brave เปิดตัวฟีเจอร์ช่วยให้ผู้ใช้งานซ่อนอีเมลจริงและป้องกันการติดตาม บนเวอร์ชัน 1.94

      Brave เปิดตัวฟีเจอร์ช่วยให้ผู้ใช้งานซ่อนอีเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand bcfbe76b-0573-472c-9d93-f93a70395648-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ TranslatePress บน WordPress เสี่ยงถูกรีเซ็ตรหัสผ่านผู้ดูแลระบบ

      ช่องโหว่ TranslatePress บน WordPress เสี่ยงถูกรีเซ็ตรหัสผ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 34ee9ecf-1db8-40f4-8fff-bd488da6ec78-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • PaperCut เตือนช่องโหว่ Zero-Day ใน NG และ MF ถูกใช้โจมตี จำกัดการเข้าถึงทันที

      PaperCut เตือนช่องโหว่ Zero-Day ใน NG และ MF ถูกใช้โจมตี จ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 39f3947c-cc14-4d55-82b6-147ae0bb6a8a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • สหรัฐฯ ประกาศแบนอุปกรณ์โครงสร้างพื้นฐานด้านพลังงานจากต่างชาติ หวั่นภัยคุกคามทางไซเบอร์

      สหรัฐฯ ประกาศแบนอุปกรณ์โครงสร้างพื้นฐานด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand cd423c55-1d9f-444d-a286-e9b9e5cdc80c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT