NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,548
    • กระทู้ 2,549
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 4 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1d374e2e-ff1f-4266-a1c4-04f3ab63f292-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 07 September 2026

      Industrial Sector

      • IXON VPN Client
        "Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02
      • Pyramid Solutions NetStaX EtherNet/IP Stack
        "Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07
      • Inductive Automation Ignition
        "Successful exploitation of this vulnerability could allow any authenticated user to create projects."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06
      • Tycon Systems TPDIN-Monitor-WEB3
        "Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08
      • OPCFoundation OPC UA LocalDiscoveryServer (LDS)
        "Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01
      • Rockwell Automation ControlFLASH
        "Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03
      • Rockwell Automation ArmorStart LT
        "Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04
      • Rockwell Automation 1756-ENBT Module
        "Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05

      Vulnerabilities

      • Critical Citrix NetScaler Auth Bypass Now Leveraged In Attacks
        "Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured."
        https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/
      • Google Warns Of New Chrome Zero-Day Flaw Exploited In Attacks
        "Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as “Serotav.” The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the advisory reads."
        https://www.bleepingcomputer.com/news/security/google-warns-of-new-chrome-zero-day-flaw-exploited-in-attacks/
        https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html
        https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/
        https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026.html
        https://www.helpnetsecurity.com/2026/09/04/google-chrome-zero-day-cve-2026-85046/
      • StyleSmuggler: Magento And Adobe Commerce 0-Day RCE Under Active Attack
        "Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current versions are affected, including 2.4.9. Attacks started September 4th. Sansec is rolling out emergency mitigation."
        https://sansec.io/research/stylesmuggler
        https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html
      • Critical Vulnerabilities In MikroTik RouterOS Are Being Actively Exploited. Immediate Update Recommended
        "The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS. Combining two of them allows an attacker to take full control of the device without authentication if the device supports remote access using the SSH protocol. To make this chain easier to identify, we have given it a common name, MikroTrick. In recent days we have been observing attacks against RouterOS devices accessible from the internet. We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks. It has also been confirmed that the released patches prevent the observed attacks. We recommend applying the update immediately."
        https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
        https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
        https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog
        https://securityaffairs.com/198455/security/u-s-cisa-adds-google-chromium-v8-flaw-to-its-known-exploited-vulnerabilities-catalog-2.html
      • PostGREShell: The Database Powering Much Of The Internet Had An Open Door For 12 Years
        "Imagine you've built a fortress. Guards at the front gate, scanners at every door, a guest list checked twice. You hired the best architects, ran the audits, passed the compliance reviews. By every measure, the place is locked down. But you missed something. Around the back, there's a small, unmarked entrance used by the cleaning crew. It's been there for years, and nobody thought to put a guard on it. Then one day, someone figures out that if you walk in through that entrance wearing a cleaning uniform, the entire fortress opens up: the armory, the vault, the control room. Once you're inside, everyone assumes you belong."
        https://www.cyera.com/research/postgreshell-the-database-powering-much-of-the-internet-had-an-open-door-for-12-years
        https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html
        https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/
        https://securityaffairs.com/198433/security/postgresql-hit-by-12-year-old-vulnerability-allowing-server-takeover.html

      Malware

      • Attack Cases In Korea Involving The Installation Of Radmin And UltraVNC
        "The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the infected systems as proxy nodes. Recently, they have been installing SoftEther VPN to exploit the infected systems as VPN servers."
        https://asec.ahnlab.com/en/95230/
      • X Money Rollout Linked To Password-Reset Attacks
        "X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival alongside the wider X Money rollout has fueled account-takeover concerns, X says it has found no evidence of a breach or successful account takeovers so far."
        https://www.malwarebytes.com/blog/scams/2026/09/x-money-rollout-linked-to-password-reset-attacks
      • Angry Birds: Toy Ghouls’ New Toys
        "We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In early July 2026, we observed the group using a custom backdoor for the first time. We identified two versions of this backdoor: one uses the HiveMQ MQTT broker as its C2 server, while the other relies on the Element messenger."
        https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/
      • ASCII Smuggling Crosses Over From AI Prompt Injection To Phishing Evasion
        "Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them. The finding emerged from Microsoft Defender for Office 365 prompt injection protection research, showing how AI-era evasion techniques can surface in traditional phishing campaigns. In Microsoft telemetry, hits on a hunting signature designed to detect ASCII-smuggling increased sharply beginning February 9, 2026, and remained elevated on weekdays for approximately three months. Microsoft Defender for Office 365 telemetry showed that the majority of messages were flagged by layered protections rather than by reliance on a single Unicode-specific signal."
        https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
        https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html
        https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/
        https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595
      • DPRK APTs: Ted Backdoor And CurlRAT Target South Korean Media And Automotive Sectors
        "A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance."
        https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/
        https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html
      • Attackers Actively Exploiting Critical Vulnerability In Super Forms Plugin
        "On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July 8th, 2026, and we disclosed this vulnerability in the Wordfence Intelligence vulnerability database on July 9th, 2026. Our records indicate that attackers started exploiting the issue on July 14th, 2026, the same day we released the firewall rule. The Wordfence Firewall has already blocked over 250,000 exploit attempts targeting this vulnerability."
        https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/
        https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
      • Chinese-Speaking Operator Uses AI Agents To Target Government And Education Systems Across Asia
        "In July, we published research on a Chinese-speaking operator who embedded Claude Code and DeepSeek into intrusions across four countries. This is a second, separate campaign with different infrastructure, tooling, and targets, but the same pattern: commercial AI models used as operational components. Targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The most extensive compromise hit a Fengtai District government environment, where the operator achieved command execution, collected LSASS and registry hives, accessed government and health records, and deployed multiple Windows implants. Separate activity exposed a Chinese education AI platform and obtained root database access to a university campus-card system."
        https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia
        https://securityaffairs.com/198417/ai/chinese-hackers-use-ai-agents-in-multi-country-cyber-campaign.html
      • Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations
        "Datadog Security Research observed a password spraying campaign targeting the AWS root user account. The campaign ran from July 24 to August 23, 2026. During this period, attackers made repeated failed authentication attempts against AWS root user accounts at more than 150 organizations. Organizations saw a median of two attempts each, with some experiencing up to eight attempts across the campaign window."
        https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/
      • Chained Account Takeovers: AiTM Phishing Campaign Propagating Across Healthcare And Academic Medical Institutions
        "SRA identified an active adversary-in-the-middle (AiTM) phishing campaign propagating across healthcare and healthcare-education organizations by chaining compromised accounts. SRA reconstructed one chain across a university and two health systems, where a single compromised account phished recipients at more than 90 distinct .edu domains in roughly 13 minutes. Open-source analysis shows the observed chain is a part of a broader operation that pairs credential and session theft with a parallel malware delivery track, masking its infrastructure so effectively it scores clean on public reputation tools. Organizations in healthcare and higher education should hunt for the redirect and inbox-rule patterns detailed below, confirm session-token revocation on any affected account, and prioritize phishing-resistant MFA."
        https://sra.io/blog/chained-account-takeovers-aitm-phishing-campaign-propagating-across-healthcare-and-academic-medical-institutions/
      • Anatomy Of a Silent Domain Takeover
        "Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single attack. A full domain takeover can be completed in 54 minutes, from the first password spray to the forged Golden Ticket, with each individual event appearing normal."
        https://blog.qualys.com/product-tech/2026/09/02/anatomy-of-a-silent-domain-takeover-ad-real-time-monitoring
      • Malware On The Blockchain: An Ongoing Campaign’s New WebRTC Twist
        "EtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised websites in the last few months. The compromised websites have little in common beyond being small businesses (clinics, plumbers, e-commerce shops) with no shared industry, region, or owner. These compromised sites include either an inline script or a spoofed package that calls the BSC testnet and downloads a ClickFix overlay as the next step of the attack, which instructs visitors to run a command on their PC. We also observed a newer variant that, instead of a ClickFix overlay, opens a covert WebRTC data channel for Command and Control."
        https://www.netskope.com/blog/malware-on-the-blockchain-an-ongoing-campaigns-new-webrtc-twist
        https://www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/
      • Discovery Of a New OpenAI Agent Message Board
        "We found ~18,000 posts from autonomous AI agents (self-identifying as from OpenAI) using the public internet to communicate during a web-retrieval task. These AIs colluded to share answers, research their environment, and bypass sandbox restrictions. Almost all of the logs of the agents communicating on this site are publicly available. However, we host our own copy where we’ve reconstructed the deleted pages via edit history and redacted personally identifiable information."
        https://collusion.wiki/
        https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/
        https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html
        https://securityaffairs.com/198524/ai/ai-agents-hijacked-german-wiki-to-cheat-openai-delayed-disclosure.html
      • Attackers Exploit PaperCut Flaws To Steal Credentials From Schools And Universities
        "Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts. "Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf said."
        https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html
        https://securityaffairs.com/198476/hacking/papercut-flaws-exploited-in-attacks-on-u-s-and-european-schools.html
      • REVSTEALER Ramps Up: Analysis Of Up-And-Coming Infostealer
        "Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months, with higher distribution volume, and has emerged as a formidable threat, featuring a comprehensive credential harvester, an embedded sandbox scoring system, and a Polygon blockchain-based dead drop for resilience. Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets."
        https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer
        https://assets.contentstack.io/v3/assets/bltefdd0b53724fa2ce/blt9cd59668ba5a104d/6a97978bd04dac6f166ca8ce/REVSTEALER_-_White_paper.pdf
      • Detection And Removal Of The Syslogk Rootkit In a Linux Environment
        "The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. This document provides an analysis of the key features and operational mechanisms of the Syslogk rootkit, along with detection and remediation strategies for our products developed based on this analysis."
        https://asec.ahnlab.com/en/95254/

      Breaches/Hacks/Leaks

      • Cybercrooks Trawl Fishbrain To Net Password Hashes
        "Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts."
        https://www.theregister.com/cyber-crime/2026/09/03/cybercrooks-trawl-fishbrain-to-net-password-hashes/5294158
      • Attackers Breached JetBrains Cadence Via Unpatched TeamCity, Extracting AWS Credentials
        "JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said. "They should also treat all executions, including their inputs and outputs in your Cadence project, as potentially untrusted.""
        https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html
      • Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
        "Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets."
        https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html

      General News

      • Why Judgment Is Emerging As Cybersecurity’s Defining Skill
        "AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a technically sound recommendation is also getting easier, which puts more weight on the judgment about what to do with it. A recommendation can make complete sense from a security perspective and still carry consequences for the systems, people and business around it that change what the right decision is."
        https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/
      • Insurers Search For Answers To Rein In Rogue AI
        "When Maria Long heard about OpenAI's rogue model attacking AI-model service provider Hugging Face, her first stop was to review her firm's technology errors and omissions (Tech E&O) policy. As the chief underwriting officer for cybersecurity insurance services firm Resilience, she understood that rogue AI agents causing inadvertent compromises could result in significant losses to insurers in the future. This incident showed that the future wasn't that far off. For Hugging Face, the incident would almost certainly be covered by cyber-liability insurance as a classic security breach. However, if AI agents routinely escape containment, insurers have to consider that the volume of policy claims could grow."
        https://www.darkreading.com/cyber-risk/insurers-search-answers-rogue-ai
      • What The AI Warning Letter Completely Missed
        "Recently, more than 100 technology companies — OpenAI, Anthropic, Microsoft, and Google among them — published an open letter warning that AI is about to make sophisticated cyberattacks far cheaper and far more common, and that "we have a limited window to strengthen cyber defenses." I read it twice. The first time as the head of a security organization, nodding along to very nearly every line. The second time hunting for the part about who actually does the work. I did not find it."
        https://www.darkreading.com/cyberattacks-data-breaches/ai-warning-letter-missed-people
      • Companies Have 6 Months To Prepare For Automated Attacks
        "With multiple benchmarks confirming that at least one frontier model can autonomously execute an end-to-end compromise, cybersecurity experts are warning that companies have to pick up the pace in securing their attack surfaces and adopting AI-speed defenses. On Sept. 2, consulting firm Booz Allen became the latest organization to confirm that a frontier model — Anthropic's Mythos 5 — can act as a fully autonomous hacker and compromise a production-grade enterprise network. The company also released a metric, dubbed the Cyber Weapon Index (CWI), to benchmark a model's capabilities, pairing the ability to find and exploit vulnerabilities with the ability to execute and attack a target."
        https://www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks
      • AI Is Ending The Era Of Hidden Vulnerabilities — Are Vendors Ready?
        "Vulnerabilities are running out of places to hide, thanks to frontier AI models, and it could create problems for those that sell software. The "vulnpocalypse," or the onslaught of vulnerabilities surfaced through the proliferation of AI, is having far-reaching consequences on the economics and demands previously associated with bug hunting. Software publishers are used to operating in a world where code reviews, researcher attention, and discovery capacity are finite. But over the past two years, things have changed. Large language models (LLMs) have automated and sped up large portions of the bug discovery pipeline, and frontier models could accelerate that process even further."
        https://www.darkreading.com/vulnerabilities-threats/ai-ending-era-hidden-vulnerabilities-are-vendors-ready
      • US Offers $10 Million For Info On Iranian Allegedly Behind Cyberattacks On Critical Infrastructure
        "A $10 million reward has been posted by the State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps’ (IRGC) Cyber-Electronic Command (CEC). U.S. officials accused Yaryab of directing multiple Iranian hacking groups that have targeted “critical infrastructure sectors including defense, news, shipping, travel (hotels and airlines), energy, and financial and telecommunications systems in the United States, Europe, and the Middle East.”"
        https://therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks
      • H1 2026 Malware And Vulnerability Trends
        "H1 2026 activity showed a continued adversary preference for abusing legitimate tools, trusted platforms, and routine workflows already present in enterprise and consumer environments. Threat actors used exposed software, developer tools, remote access utilities, payment workflows, and third-party services to gain access, steal credentials, move laterally, and monetize intrusions while blending into expected activity. This emphasis on evasion through normalcy rather than technical novelty increases the risk that malicious activity will progress through approved tools and trusted services before defenders recognize it, reinforcing the need for stronger exposure management, identity and credential governance, behavioral detection, developer-environment security, backup resilience, mobile fraud monitoring, and third-party oversight."
        https://www.recordedfuture.com/research/h1-2026-malware-vulnerability-trends
        https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0903.pdf

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) a0344717-380a-49ff-969f-52d35634883f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 04 September 2026

      Vulnerabilities

      • HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw
        "Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges. “Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input,” reads HPE’s bulletin."
        https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/
      • Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code As Root
        "Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance."
        https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html
        https://www.securityweek.com/cisco-warns-of-unpatched-secure-email-flaws-patches-critical-switch-vulnerabilities/
        https://securityaffairs.com/198366/security/cisco-fixed-critical-rce-in-nexus-9000-series-switches.html
      • Plex Warns Users To Patch Security Vulnerabilities Immediately
        "Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. These flaws have not yet been assigned CVE IDs for easy tracking, and while Plex didn't provide additional details on Tuesday, the security issues are known to affect Plex Media Server v1.43.2 and earlier. Plex also emailed users running affected versions and asked them to update as soon as possible to address these security flaws."
        https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
      • VMSA-2026-0007: VMware Workstation And Fusion Updates Address Integer-Overflow And Buffer Overflow Vulnerabilities (CVE-2026-59346, CVE-2026-59347)
        "An integer-overflow and a buffer-overflow vulnerabilities in VMware Workstation and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products."
        https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288
      • Attackers Actively Exploiting Critical Vulnerability In Elementor Pro Plugin
        "On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site takeover. The vendor released the fully patched version on August 19th, 2026, and we originally disclosed this vulnerability in the Wordfence Intelligence vulnerability database on the same day. The Wordfence Firewall has already blocked over 190,000 exploit attempts targeting this vulnerability."
        https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/
        https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/

      Malware

      • Coder's Registry Infrastructure Compromised To Push Malicious Modules
        "Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. The Coder platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications. The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the U.S. government, and defense companies."
        https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/
      • The NDA Was The Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign
        "It started with an innocent WhatsApp message. “Hi David, I hope you are well. Are you at the office?” The sender claimed to be a real Gen executive based in Dublin. The profile used his name, photograph and an Irish telephone number. Nothing in the opening message mentioned money, urgency or an acquisition. It was simply designed to establish whether the recipient was available and willing to respond. The recipient, whom we will call David, worked in Gen’s legal team and knew the colleague being impersonated. The unfamiliar telephone number raised suspicion, and the first phone conversation confirmed it: the caller’s voice did not match."
        https://www.gendigital.com/blog/insights/research/phantom-deal
        https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams
      • Someone Else Is Using Your AI
        "Generative AI is quickly becoming one of the more lucrative uses for stolen cloud credentials. Attackers no longer need to set up crypto miners or exfiltrate data to cash in on a leaked IAM key. They can instead subscribe to foundation models through AWS Marketplace and resell inference access, a technique called LLMjacking, first documented in 2024. FortiCNAPP recently investigated a case that shows how fast and mechanical that pivot has become. FortiGuard Labs recently analyzed a long-lived AWS IAM access key with administrator privileges that was used to create a new IAM identity, subscribe it to foundation models on AWS Marketplace, and begin invoking them."
        https://www.fortinet.com/blog/threat-research/someone-else-is-using-your-ai
      • The Outsider Phishing Kit: A Resilient Threat In The Face Of Law Enforcement Action
        "During an investigation into phishing kits sold, Group-IB researchers uncovered the “Outsider Phishing Kit” (局外人), a sophisticated Phishing-as-a-Service (PaaS) platform operated by the threat actor known as “ChenLun.” The kit incorporates Adversary-in-the-Middle (AiTM) capabilities, enabling attackers to intercept authentication flows and bypass multi-factor authentication (MFA). The scale of this operation is staggering. From December 2025 to May 2026, Group-IB has identified over 100,000 phishing pages targeting 54+ countries, leveraging 267 (and growing) phishing templates. These numbers underscore the increasingly low barrier to entry for threat actors to launch and operate large-scale phishing campaigns."
        https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/
        https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/
      • Attackers Expose Ongoing AI Tool Use Targeting Organizations In Latin America
        "We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities."
        https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/
      • US Becomes Top Target In RMM Phishing Campaign Spanning 46 Countries
        "An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses fake documents to trick victims into installing legitimate remote monitoring and management (RMM) software. The attackers adapt their lures to different targets, using shipping and UPS communications, Adobe PDFs, tax notices, US Social Security Administration themes, invoices, and other documents. Rapidly rotated, disposable Vercel infrastructure makes the campaign harder to track and detect."
        https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html
      • Node.js: Old Technique Makes a Comeback
        "Between March and July 2026, attackers who compromised a technology start-up in Asia ran into a problem: almost every payload they attempted to deploy, including AdaptixC2 agents and Cobalt Strike Beacon, was blocked on the victim's network. Their response was to download the official Node.js installer from nodejs.org and use the trusted, signed runtime to execute a malicious implant. The implant maintained its foothold for months and made repeated connections to Ethereum blockchain gateways, most likely to retrieve commands or additional payloads hidden in a blockchain smart contract, a technique known as EtherHiding."
        https://www.security.com/threat-intelligence/node-js-returns-ransomware
        https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html
      • Shai-Hulud's Reach Just Grew To 469 Credential Locations. Here's What That Means
        "In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have stopped trying to break trust relationships and started using the credentials that already make those relationships work. Software supply chains have always depended on trust."
        https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html
      • Researcher Releases FalconFlank PoC Showing Privilege Escalation In CrowdStrike Falcon
        "The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in a GitHub README file, adding the cybersecurity company may already have detections for the flaw by now. "So if you want to test, you either have to add it to the exclusions or obfuscate the PoC and change the DLL load technique.""
        https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
        https://securityaffairs.com/198342/hacking/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank.html
      • Impersonating IT Support: How Threat Actors Turn a Remote Session Into Enterprise-Wide Access
        "Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session. Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2)."
        https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/

      Breaches/Hacks/Leaks

      • US And Canadian Court Data Exposed In Thomson Reuters Breach
        "Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada, the company publicly disclosed Wednesday. Thomson Reuters has not said how the attacker gained access, who was responsible or how much data was taken. The number of people affected also remains unclear. The company stressed the breach occurred within its environment and was not caused by the networks, systems or data security of the affected courts."
        https://therecord.media/thomson-reuters-cyberattack-data
        https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html
        https://www.infosecurity-magazine.com/news/us-canada-court-breach-thomson/
        https://www.helpnetsecurity.com/2026/09/03/thomson-reuters-reveals-breach-that-exposed-u-s-and-canadian-court-records/
      • Manchester Airports Group Data On 8.8 Million People Leaked After Ransom Refusal
        "Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people. MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports. The airport operator disclosed that hackers had exfiltrated email addresses, phone numbers, vehicle registrations, and postcodes, noting that its operations were not affected by the incident."
        https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/
      • 412,000 The Town 2025 Ticket Buyers’ Data Hits The Dark Web
        "A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. Ransomnews’s analysis confirms the sample is genuine ticket-buyer data from The Town 2025, the São Paulo music festival, though who actually lost the data and how remains unconfirmed. “The listing is headed “SELLING NEW TICKETMASTER DATABASE” and describes a global ticketing platform, Latin America region, with an internal ticketing database as the source and a breach date of 28 August 2026."
        https://securityaffairs.com/198354/data-breach/412000-the-town-2025-ticket-buyers-data-hits-the-dark-web.html
      • Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline
        "Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations. The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”). The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities. Field placements then moved students from classroom instruction into military units and academies aligned with their specialties, giving them supervised exposure to intelligence operations and preparing them for military and government operations careers."
        https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline
        https://securityaffairs.com/198332/intelligence/2000-leaked-documents-reveal-how-russia-turns-engineering-students-into-gru-cyber-operators.html

      General News

      • G7 Says Migrating To PQC Early Is Cheaper Than Later
        "An international public-private cyber alliance is making a call to action on transitioning to post-quantum cryptography and offers strategies to lower the cost of the strenuous effort. The G7 Cybersecurity Working Group of government agencies and banks from seven economically advanced countries along with the European Union outlined many risks that can happen after quantum computers break classic encryption and told every country to consider PQC as a "foreseeable evolution of cryptographic best practices" that cannot be avoided."
        https://www.bankinfosecurity.com/g7-says-migrating-to-pqc-early-cheaper-than-later-a-32738
        https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/asset_files/external/g7preparingfortheqostquantumeraacalltoaction.pdf
        https://cyberscoop.com/g7-quantum-computing-encryption-warning/
      • Crypto Agility: Why PQC Is Not a One-Time Upgrade
        "Crypto agility is the ability to update cryptographic algorithms, protocols, libraries, and implementations while minimizing disruption and avoiding unnecessary replacement of the underlying infrastructure. For networks, that means adopting post-quantum cryptography (PQC) while preserving the ability to accommodate future standards and defenses primarily through software. This capability matters because networking platforms often take years to develop and may remain deployed for a decade or longer."
        https://blogs.cisco.com/security/crypto-agility-why-pqc-is-not-a-one-time-upgrade
      • Supply Chain Attacks In 2026: Why Threat Intelligence Is The Only Early Warning System That Works
        "Supply chain attacks in 2026 are no longer an edge-case risk buried in a vendor questionnaire — they are a primary breach vector that regulators, incident responders, and CISOs now treat as a first-order threat. Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches, up 60% year over year, following the 2025 edition, which already recorded a jump from 15% to 30%. Every vendor integration, every open-source dependency, and every managed file transfer tool expands the attack surface that an organization does not directly control. That is the core problem with supply chain security today: the weakest link is rarely the enterprise itself."
        https://cyble.com/blog/supply-chain-attacks-in-2026-vendor-risk/
      • Your AI Agent’s System Prompt Is Not a Security Control
        "An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute, put the fix one layer down: scope the query to the user’s permissions at retrieval time, inside the role-based or attribute-based access system the company already runs, and filter the results before they reach the model’s context window."
        https://www.helpnetsecurity.com/2026/09/03/sans-aws-agentic-ai-security/
      • Your Threat Feed Is Someone Else’s Database: What Ingesting Malware Intel At Scale Takes
        "The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone else’s database. Someone else’s processes built it, someone else’s judgement calls shaped it, and someone else’s bad Tuesday is sitting it right now, waiting for the automation to act on it. I lead the team that runs Dependabot at GitHub, which monitors more than 30 million repositories for vulnerable and malicious dependencies as of 2026. This year we extended malicious-package advisories from npm, where we had been flagging malware since March, to eight package ecosystems, by ingesting community intelligence from OpenSSF’s malicious-packages repository."
        https://www.helpnetsecurity.com/2026/09/03/github-threat-intelligence-feed-ingestion/
      • When AI Quietly Breaks Things, Who Pays?
        "David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures in applications can turn into warranties an insurer uses to deny a claim, who should sign off on AI use questions, when the claim clock starts for slow-building model degradation, and how business interruption coverage applies to outages at cloud and compute vendors."
        https://www.helpnetsecurity.com/2026/09/03/david-halbreich-reed-smith-ai-insurance-coverage-gaps/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e52ccc9b-7672-4b70-bd36-017039b11b7b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีช่องโหว่ StyleSmuggler ใน Magento และ Adobe Commerce เสี่ยงรันโค้ดและฝัง Backdoor

      พบการโจมตีช่องโหว่ StyleSmuggler ใน Magento และ Adobe Commerce เสี.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5e803fd4-d4bc-42eb-8884-fac403ec6c4a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Broadcom ออกแพตช์แก้ช่องโหว่ VM Escape ระดับ Critical ใน VMware Workstation และ Fusion

      Broadcom ออกแพตช์แก้ช่องโหว่ VM Escape ระดับ Critical ใน VMware Wor.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 59e809e5-7e23-4bc9-8934-c224cd4aed7f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ตรวจพบการโจมตีผ่านช่องโหว่บนอุปกรณ์ MikroTik ควบคุมระบบได้โดยไม่ต้องยืนยันตัวตน

      ตรวจพบการโจมตีผ่านช่องโหว่บนอุปกรณ์ MikroTik ค.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6242a404-46a1-488f-8919-31097a6e4b1c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน All-in-One WP Migration and Backup เสี่ยงรันโค้ดบนเว็บไซต์ WordPress

      ช่องโหว่ใน All-in-One WP Migration and Backup เสี่ยงรันโค้ดบนเว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2347a33f-e4f2-4386-a95c-5e5072d4bbe4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • SonicWall ออกแพตช์แก้ 2 ช่องโหว่ Zero-Day ใน SMA 1000 VPN หลังพบถูกใช้โจมตี

      SonicWall ออกแพตช์แก้ 2 ช่องโหว่ Zero-Day ใน SMA 1000 VPN หลังพบ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd35ab0a-1bbe-4e84-945d-f20709927067-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตรียมรับมือ OpenAI ยืนยันแล้ว AI โมเดล Astra สามารถค้นหาช่องโหว่ Zero-day และสร้างโค้ดโจมตีได้โดยอัตโนมัติ

      เตรียมรับมือ OpenAI ยืนยันแล้ว AI โมเดล Astra สามารถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1a7058cd-8c11-4531-825b-7edebc36cbc9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 7 รายการลงในแคตตาล็อก

      เมื่อวันที่ 2 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 7 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability
      • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability
      • CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability
      • CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability
      • CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability
      • CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
      • CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3c91a749-877e-4e48-8f87-4ccbaa8c6acb-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 03 September 2026

      Vulnerabilities

      • Off The Hook: Discovering And Observing Active Exploitation Of Sangoma Switchvox CVE-2026-9586
        "At Horizon3, we’re constantly looking for technologies and applications to perform security audits on that we believe may be targeted by threat actors. In April of 2026, we took a look at the Sangoma ecosystem after several FreeBPX vulnerabilities, CVE-2025-57819 and CVE-2025-64328, landed on the CISA Known Exploited Vulnerabilities (KEV) catalog. One such application we landed on was Sangoma Switchvox. Switchvox is an enterprise VoIP telephony management solution. It allows organizations to easily configure phone systems to include voicemail, call forwarding, and monitoring and analytics across their enterprise."
        https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/
        https://www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/
        https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html
        https://www.helpnetsecurity.com/2026/09/02/exploitation-of-sangoma-switchvox-flaw-underway-cve-2026-9586/
      • SonicWall Warns Of Actively Exploited SMA1000 Zero-Day Flaws
        "SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. The first is a maximum-severity command injection flaw (CVE-2026-83548) found in the SMA1000 Appliance WorkPlace interface that stems from a server-side request forgery (SSRF) weakness. This actively exploited zero-day chain also targets a command injection vulnerability (CVE-2026-83549) in the SMA1000 Appliance Management Console that attackers with admin privileges can exploit to execute arbitrary OS commands on vulnerable devices."
        https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/
        https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
        https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html
        https://www.darkreading.com/vulnerabilities-threats/sonicwall-sma-1000-zero-days-unauthenticated-rce
        https://www.infosecurity-magazine.com/news/hackers-chain-sonicwall-zeroday/
        https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/
        https://securityaffairs.com/198303/security/sonicwall-patches-two-new-actively-exploited-zero-days-in-sma-1000-vpns.html
        https://www.helpnetsecurity.com/2026/09/02/sonicwall-sma-1000-cve-2026-83548-cve-2026-83549-zero-day-attacks/
      • 5 Million WordPress Sites Affected By SQL Injection Vulnerability In All-In-One WP Migration And Backup WordPress Plugin
        "On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations. This vulnerability makes it possible for unauthenticated attackers to inject SQL that is later executed when a site administrator performs an archive restore, which can be used to leak the plugin’s secret key and ultimately achieve remote code execution, leading to complete site takeover."
        https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/
        https://www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/
      • GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
        "Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and Agriculture Organization and is maintained under the Open Source Geospatial Foundation (OSGeo). It is a core component of many Spatial Data Infrastructure deployments across Europe and beyond, including the backend of the European INSPIRE geoportal."
        https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html
      • Chrome And Firefox Updates Patch Dozens Of Vulnerabilities
        "Google and Mozilla on Tuesday announced patches for dozens of vulnerabilities across Chrome and Firefox, including critical- and high-severity flaws. A fresh Chrome 152 update has been rolled out with fixes for 26 bugs, two of which are critical-severity use-after-free issues in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352). The update also addresses nine high-severity security defects, including use-after-free, incorrect authorization, information leak, improper input validation, uninitialized resource, and buffer overflow weaknesses."
        https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/
        https://www.malwarebytes.com/blog/bugs/2026/09/two-critical-chrome-flaws-put-users-at-risk-on-malicious-websites
      • CISA Adds Seven Known Exploited Vulnerabilities To Catalog
        "CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability
        CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability
        CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability
        CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability
        CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability
        CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
        CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog
      • Eight Findings Across Seven Agents. Four Remain Unpatched At Publication.
        "What it is. AI coding agents run git commands in the background to gather context, on some agents before you type a prompt, before the workspace-trust prompt, before you have even authenticated. Improper sanitization in this context-gathering mechanism is a widespread security vulnerability across AI coding agent products, each ending in arbitrary code execution. What an attacker gets. Arbitrary code execution as the developer, outside the sandbox, with no approval prompt and nothing on screen. Their SSH keys, the cloud credentials in their environment, the tokens in their shell config, every repository on disk, and a foothold on the machine. How widespread. Not one vendor’s bug. Claude Code ships over 77 million npm downloads a month (as per npm API). Across the five projects, Hermes carries over 237,000 GitHub stars, Claude Code 143,000+, Goose 54,000+, Qwen Code 27,000+ and Grok Build 26,000, close to half a million together."
        https://www.manifold.security/blog/ai-coding-agents-git-hijack
        https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html
      • Exploit Published For Fresh Cleo Harmony Vulnerability
        "Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony. Tracked as CVE-2026-84115, the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument bearer manipulation. The flaw was discovered in an unknown function in the file ‘/api/connections’. An attacker could craft a malicious payload that tampers with the arguments in HTTP headers, bypassing access controls and leading to privilege escalation."
        https://www.securityweek.com/exploit-published-for-fresh-cleo-harmony-vulnerability/
        https://vuldb.com/cve/CVE-2026-84115

      Malware

      • Kim Sooki Again? This Time, It Was Disguised As a Request For Seafood Ingredients
        "A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. It then extracts system information to an external location, downloads and executes additional commands, and wipes all traces. Let’s examine the tactics used by a malicious LNK file linked to Kimsuky, which disguises the attack by masquerading as a legitimate business document."
        https://asec.ahnlab.com/en/95217/
      • “Evasive” Malware Attack Tactics: Hiding, Bypassing, And Reappearing
        "People who initially seem fine but tend to subtly avoid others as the relationship deepens or when conflicts arise—and who disappear when pressured—are commonly referred to as “avoidant types.” By repeatedly pulling away only to reappear, they drain the other person’s emotions and energy, ultimately undermining the relationship. The attack pattern of the recently identified “MoiClient” backdoor exhibits similar behavior. It lowers users’ guard by disguising itself as an invoice, executes while hidden within legitimate programs, and finds alternative paths whenever it encounters security controls. It bypasses permission controls and exploits vulnerable drivers to neutralize even security products designed to block it, while repeatedly executing itself through the Task Scheduler. Let’s take a closer look at MoiClient’s attack method: it bypasses obstacles when blocked and hides again when attempts are made to detect it."
        https://asec.ahnlab.com/en/95211/
      • Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites To Fuel a Global SEO Fraud Machine
        "Check Point Research has been tracking a sustained campaign, active since mid-2025, that marks a real shift in how and where cyber crime targets trusted infrastructure. The group behind it, which CPR dubbed, “Gambling Goblin”, is a Chinese-speaking cybe rcrime cluster tied to Earth Berberoka, previously documented targeting gambling sites across Asia. Its playbook: compromise trusted, high-reputation web servers and turn them into infrastructure for a global SEO fraud operation."
        https://blog.checkpoint.com/research/gambling-goblin-a-chinese-speaking-actor-hijacks-brazilian-government-sites-to-fuel-a-global-seo-fraud-machine/
        https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/
        https://thehackernews.com/2026/09/malicious-apache-modules-hijack.html
        https://www.infosecurity-magazine.com/news/gambling-goblin-brazilian/
      • Pegasus Spyware Infection Of Serbian Pro-Democracy Student Activist
        "In collaboration with the SHARE Foundation, the Citizen Lab analyzed forensic artefacts from the iPhone of a member of Serbia’s student protest movement after they received an Apple Threat Notification warning of targeting with mercenary spyware. Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware. We found high-confidence indicators of infection from a period across December 2025 – January 2026, however this does not preclude the possibility of additional infections."
        https://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/
        https://cyberscoop.com/pegasus-novispy-variant-spyware-found-on-devices-of-serbian-activists/
      • Tech Support Scams Look Different Now. Here’s What To Watch For
        "In a tech support scam, criminals pretend to work for a trusted technology or security company. They claim there is a problem with your device, software, subscription, or account, then try to persuade you to pay them, share personal information, or give them remote access to your computer. These scams used to rely mainly on browser locks and fake virus warnings. Now, scammers use many more ways to reach people, including websites and platforms they trust."
        https://www.malwarebytes.com/blog/scams/2026/09/tech-support-scams-look-different-now-heres-what-to-watch-for
      • Kali365 And Why Stealing Passwords Is No Longer Enough
        "Attacks abusing authentication processes are on the rise. Since early 2026, Kali365, a phishing-as-a-service (PhaaS) platform targeting Microsoft 365 environments, has abused authentication processes in waves of attacks. A number of cybersecurity vendors and the FBI have reported on Kali365, and Barracuda researchers have seen many Kali365 attacks in recent months. This article details Barracuda’s findings."
        https://blog.barracuda.com/2026/09/02/kali365-phishing-microsoft-365-authentication-abuse
      • Counterfeit Installers To System Compromise: Tracking a Deceptive Software Download Campaign
        "Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors."
        https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/
        https://thehackernews.com/2026/09/fake-software-installers-disable.html
      • Uncovering StreamRat: From Meta Ads To Full Device Takeover
        "ThreatFabric researchers have uncovered StreamRat, a new Android banking trojan promoted to Spanish-speaking users through Meta and TikTok advertisements impersonating a free TV-streaming service, with the campaign reaching approximately 570,000 potential victims. Following a two-stage installation, StreamRat abuses Accessibility Services and MediaProjection to provide operators with near-complete control over infected devices, combining VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, internet and screen-blocking capabilities."
        https://www.threatfabric.com/blogs/from-meta-ads-to-full-device-takeover-uncovering-streamrat
        https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html
      • New Pro-Ukraine Hacker Group Targets Russian Companies With Custom Ransomware
        "A ransomware group believed to be linked to pro-Ukrainian hackers is targeting Russian organizations with custom malware and demanding multimillion-dollar payments, according to new research. The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week. Researchers first detected its activity in August, although the group's data-leak website appears to have been created in early June."
        https://therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia
      • An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
        "Unit 42 responded to an incident where a human attacker used frontier AI to breach an enterprise network autonomously as part of a ransomware attack. The agents breached the company's security layers in a methodical manner, each targeting a different layer of defense to achieve a shared goal. The impact was at the scale of a coordinated effort from multiple red teams, which would normally take human operators around two weeks."
        https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/
      • EtherHiding In The Browser: ClickFix Chain Ends In Amatera
        "Netskope Threat Labs has been tracking a WordPress mass-compromise campaign affecting hundreds of sites. On each one, a rogue must-use plugin registers a Service Worker in the visitor’s browser. That worker strips the site’s Content-Security-Policy header and injects a script that reads its payload from a smart contract on Base. In turn, the smart contract serves a fake reCAPTCHA telling the visitor to paste a command into the Windows Run dialog. The campaign employs Service Worker persistence, EtherHiding on-chain payload delivery, fake reCAPTCHA, and ClickFix, also adding a disguised polyglot file, mshta abuse, a fileless PowerShell stage, an image-hidden loader, and finally the Amatera password stealer. That is a lot of technique for one password stealer."
        https://www.netskope.com/blog/etherhiding-in-the-browser-clickfix-chain-ends-in-amatera
      • Trapping a Mustang Panda
        "As of mid-2026, IBM X-Force continues to monitor cyber campaigns conducted by ITG27, a China-aligned state-sponsored espionage group whose victims align with China’s regional strategic interests. In collaboration with Deception.Pro, X-Force captured live ITG27 activity in simulated enterprise environments, including the deployment of a previously undiscovered VNC-capable backdoor named Havencode. The observed activity extends a campaign previously reported by Acronis, where ITG27 targeted India’s energy sector and government organizations. This campaign relied on the use of Claimloader malware, lure documents, and the Toneshell backdoor. The campaign coincides with intensifying China-India competition over regional hydropower and India’s expanding strategic relationships with partners such as Taiwan."
        https://www.ibm.com/think/x-force/trapping-a-mustang-panda

      Breaches/Hacks/Leaks

      • Dropbox Accounts Breached Through Lenovo Email Verification Flaw
        "Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs. Although some affected users did not have Lenovo accounts, the cloud-storage provider said it uses Lenovo Identity Provider Services as part of its authentication infrastructure. This allows users to log into Dropbox accounts using verified Lenovo IDs. According to the notification sent to impacted users, the unauthorized access was possible due to "an issue with Lenovo's email verification process," which "allowed an unauthorized party to register a Lenovo ID using your email address.""
        https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/
      • FBI Probes Service Selling 153M+ Drivers Licenses
        "A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images."
        https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
        https://www.malwarebytes.com/blog/news/2026/09/dark-web-site-puts-153-million-drivers-licenses-and-millions-more-ids-up-for-sale
      • Hackers Expose Donor Data From Russian Fundraisers For Ukrainians, Political Prisoners
        "Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information. The unknown threat actor targeted Davayte, which raises money for civilians in Ukraine affected by Russia’s invasion, and You Are Not Alone, a project supporting Russian political prisoners and their families."
        https://therecord.media/hackers-russia-fundraisers-ukraine

      General News

      • Communicating Under Pressure: Best Practices For Service Providers
        "Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts."
        https://www.cisa.gov/resources-tools/resources/communicating-under-pressure-best-practices-service-providers
        https://www.cisa.gov/sites/default/files/2026-09/joint-guidance-communicating-under-pressure-508c.pdf
      • Russian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of Victim Users Worldwide For Financial Gain
        "A federal grand jury has indicted Searzhudin Tamirlanovich Aktulaev on charges of Conspiracy, Transmission of a Program, Information, Code, and Command to Cause Damage to a Protected Computer, and Aggravated Identity Theft, among other offenses. Defendant was arrested in Cyprus in May 2025 and has been extradited to the United States. Yesterday, he made his initial appearance in federal court in San Francisco, and he was remanded to federal custody."
        https://www.justice.gov/usao-ndca/pr/russian-national-indicted-exploiting-online-platform-used-freelance-employment-and
        https://www.bleepingcomputer.com/news/security/us-charges-russian-for-infecting-80-000-freelancers-with-malware/
        https://thehackernews.com/2026/09/extradited-russian-hacker-faces-charges.html
        https://therecord.media/russian-national-facing-20-years-malware-campaign
        https://www.infosecurity-magazine.com/news/russian-man-extradited-malware/
      • Global Public-Private Operation Disrupts Sality Botnet Active For Two Decades
        "An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to distribute malicious payloads to thousands of infected computers worldwide. The coordinated action, carried out on 31 August 2026 and led by the US authorities, targeted a botnet believed to have been operating for more than two decades. At its peak, the botnet gave its operator access to up to one million infected machines worldwide. To date, more than 11 million unique IP addresses have been linked to the infrastructure, which could be used to distribute malicious payloads to compromised devices."
        https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades
        https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html
        https://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/
        https://therecord.media/sality-botnet-cyber-doj
        https://www.bankinfosecurity.com/global-public-private-action-disrupts-russia-linked-sality-botnet-a-32732
        https://cyberscoop.com/sality-botnet-dismantled/
        https://www.securityweek.com/23-year-old-sality-p2p-botnet-disrupted/
        https://www.helpnetsecurity.com/2026/09/02/sality-botnet-disruption-crowdstrike-law-enforcement/
      • AI Gives Cybercriminals a Dangerous Time Advantage
        "Brett Johnson has seen cybercrime from both sides. Once dubbed the "original Internet Godfather" by the US Secret Service, Johnson built and ran Shadow Crew, an early organized cybercrime community, before eventually leaving that life behind. Now, he works with law enforcement and businesses to help defend against the kinds of threats he once deployed. In this conversation with Dark Reading's Kristina Beek, Johnson shares what he spoke about at Black Hat USA in Las Vegas alongside Illumio, demonstrating how artificial intelligence (AI) can compress the time it takes to carry out an attack."
        https://www.darkreading.com/threat-intelligence/ai-gives-cybercriminals-dangerous-time-advantage
      • AI’s Vulnerability Surge May Be More Manageable Than First Feared
        "A new study suggests that while AI is rapidly accelerating vulnerability discovery, enterprise organizations are better equipped to handle the surge than generally assumed. The key is their ability to quickly validate findings, prioritize risk and get available fixes into production. Software supply chain security firm Echo recently analyzed nearly 40,000 CVE life cycles across 250 open source container projects, drawing on a year of its own platform telemetry, survey responses from more than 80 security leaders, and an independent analysis of Anthropic's Claude Mythos."
        https://www.darkreading.com/application-security/ai-vulnerability-surge-manageable-than-first-feared
      • The Industrialization Of Cybercrime In Africa
        "INTERPOL’s newly released African Cyberthreat Assessment Report 2026 highlights a defining shift in the threat landscape: Cybercrime has evolved from isolated incidents into an industrialized, borderless ecosystem. That conclusion closely aligns with FortiGuard Labs’s global observations and forecasts for 2026. Criminal groups now operate as coordinated enterprises rather than just individual threat actors, supported by specialized service providers, shared infrastructure, automated tools, and mature supply chains."
        https://www.fortinet.com/blog/industry-trends/the-industrialization-of-cybercrime-in-africa
        https://www.interpol.int/en/News-and-Events/News/2026/INTERPOL-report-finds-AI-linked-to-more-than-half-of-cybercrime-in-Africa
      • A Battery Storage Cyberattack Would Look Exactly Like a Badly Tuned Controller
        "Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should not have the command, would look the same on a control room screen right up to the moment the network starts disconnecting customers. Rafael Narezzi, chief executive of the London firm Centrii, puts the number needed at 1,500 units in Texas, 5.4 percent of the ERCOT fleet, and 400 units in Great Britain, about 29 percent of the fleet there."
        https://www.helpnetsecurity.com/2026/09/02/grid-battery-storage-cyberattack/
      • National Life Group CISO Expects More Vulnerabilities In Six Months Than In Thirty Years
        "In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot keep up, and which compensating controls buy time when an immediate fix is not possible. It includes numbers from agentic AI in the security operations center, where four of five cases close without human escalation. The rest looks at questions that separate a working AI product from a wrapper, contract terms for third-party AI use, and three steps smaller banks and carriers can take in 90 days."
        https://www.helpnetsecurity.com/2026/09/02/becky-palmer-national-life-group-ai-driven-cyber-threats/
      • Scareware Ads Keep Running On Google’s Transparency Tool, Even After They’re Reported
        "A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to Google doesn’t mean the ad, or the domain behind it, stops running. The tool is called AdLens, and it comes out of a study that mined Google’s Ads Transparency Center, a public database Google built to satisfy transparency rules like the EU’s Digital Services Act."
        https://www.helpnetsecurity.com/2026/09/02/google-scareware-ads-research/
        https://racro.github.io/papers/adlens.pdf
      • Anthropic’s Enterprise Frontier Safeguards Lets Your Claude Logs Stay In Your Cloud
        "Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, spent months working with Anthropic on a question their examiners care about more than benchmark scores. Scott DePasquale, the center’s president and chief executive, said those eight defined “what it would take to run the most capable frontier models inside a systemically important bank: who holds the data, who holds the keys, what automated review can and cannot see, and under what conditions a human is ever permitted to look.”"
        https://www.helpnetsecurity.com/2026/09/02/anthropic-enterprise-frontier-safeguards/
      • An AI CAPTCHA Solver Talked Itself Out Of The Right Answer
        "You have probably spent a few seconds of your life turning a picture until it lines up. Some sites, instead of asking you to tick a box, show you a circular chunk of a photo that has been spun around, and you drag it until the inside matches the ring around it. Simple enough. Annoying enough. Two researchers at Bern University of Applied Sciences wrote a script that solves one of those in 0.006 seconds. It uses circle-detection math from the 1970s and a signal-matching technique that predates everything currently being called AI. It got all ten test puzzles right, every time, faster than you can blink."
        https://www.helpnetsecurity.com/2026/09/02/ai-captcha-solver-research/
        https://arxiv.org/pdf/2608.28794
      • Scammers Are Getting Smarter About Where They Target You
        "Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media. That’s no coincidence. Rather than blasting the same message everywhere, criminals are tailoring different scams to the platforms where they’re most likely to succeed. This finding comes from Malwarebytes’ own threat research systems and draws on global data between April 15 and July 14, 2026. The research reveals the various ways scammers are adapting their tactics and provides new insights about where they show up, when they strike, and which brands they impersonate."
        https://www.malwarebytes.com/blog/scams/2026/09/scammers-are-getting-smarter-about-where-they-target-you
      • Google, Anthropic, And OpenAI Unveil Cyber AI Models, Safeguards, And Access Programs
        "Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them build better defenses, before new threats arrive," Google said. "So defenders have an early advantage, to help them protect vital infrastructure – which in turn protects people who rely on those systems.""
        https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html
      • OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days
        "OpenAI said its newest model, Astra, has reached the ‘Critical’ cybersecurity capability level under the company’s Preparedness Framework, the first time any of its models has been placed in that category. The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems, or carry out a complete cyberattack against a hardened target from only a high-level instruction. OpenAI said the classification requires additional safeguards before the model can be released."
        https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
        https://securityaffairs.com/198317/ai/openai-astra-brings-autonomous-zero-day-exploitation-to-ai.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 3d4c42a3-f73c-4e4f-9731-f74ee4228ceb-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • WatchGuard แก้ช่องโหว่ Critical 5 รายการใน Fireware OS และ Dimension

      WatchGuard แก้ช่องโหว่ Critical 5 รายการ ใน Fireware OS และ Dimension.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 477cd472-f303-4df7-a7f4-74e3336c7e56-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Aesto Health แจ้งเหตุข้อมูลรั่วไหล กระทบข้อมูลสุขภาพกว่า 9.5 ล้านราย หลัง AWS Infrastructure ถูกเข้าถึง

      Aesto Health แจ้งเหตุข้อมูลรั่วไหล กระทบข้อมูลสุข.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand aecccdd0-3711-4ae1-9a1a-248812abe471-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตือนภัยแคมเปญ Phishing อ้างชื่อ Adobe หลอกติดตั้ง Faronics Deploy เพื่อยึดระบบ

      เตือนภัยแคมเปญ Phishing อ้างชื่อ Adobe หลอกติดตั้ง Fa.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e74bd0a0-0094-4f67-8049-68bcb88349b3-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 02 September 2026

      Industrial Sector

      • Rockwell Automation RSLinx Classic
        "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01
      • Rockwell Automation Redundancy Module Configuration Tool
        "Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-02
      • Rockwell Automation Logix Platform
        "The following versions of Rockwell Automation Logix Platform are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03
      • Rockwell Automation FactoryTalk Activation Manager
        "The following versions of Rockwell Automation FactoryTalk Activation Manager are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04
      • Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
        "The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05
      • Rockwell Automation Historian ME
        "Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06
      • Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet
        "We used AI assistance to successfully port a remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) model to another. The exercise required significant researcher involvement, including guiding the AI through dead ends, supplying disassembly context, and correcting false leads. The final RCE development stage consumed $535.74 in API tokens during an 8-hour, 32-minute session for a single exploit on a single target. An attempt to extend the exploit into a command-and-control implant bricked the PLC, highlighting how unforgiving binary exploitation on embedded targets can be."
        https://www.forescout.com/blog/can-ai-create-plc-attacks-yes-but-it’s-not-that-easy-yet/
        https://www.securityweek.com/experiment-porting-a-plc-exploit-with-ai-takes-hours-and-hundreds-of-dollars/

      Vulnerabilities

      • Nearly 22,000 Microsoft Exchange Servers Vulnerable To Hijack Attacks
        "Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. Tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction."
        https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/
      • Recently Patched PaperCut Zero-Days Used In Data Theft Attacks
        "Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions. Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers."
        https://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/
      • Attackers Pounce On Critical Artifactory Flaw Following Disclosure
        "Threat actors are actively exploiting a critical JFrog Artifactory vulnerability just days after its public disclosure, putting a fresh spotlight on the software repository platform after OpenAI's AI agents exploited zero-day flaws in the repository manager during their attack on Hugging Face earlier this year. CVE-2026-82329 is a critical (CVSS: 9.8) authentication bypass vulnerability in default configurations of Artifactory that an unauthenticated attacker can exploit to gain administrative access to the platform, with no user interaction required."
        https://www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure
        https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html
        https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/
      • WatchGuard Patches Critical Vulnerabilities
        "WatchGuard has released patches for over two dozen vulnerabilities, including five critical-severity flaws leading to remote code execution (RCE) and account takeover. Three of the critical bugs impact the iked process of Fireware OS, the core Internet Key Exchange (IKE) daemon that handles cryptographic key establishment and manages IPsec VPN negotiations over the IKEv1 and IKEv2 protocols. Exploitable without authentication, the three security defects are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315)."
        https://www.securityweek.com/watchguard-patches-critical-vulnerabilities/
      • Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague
        "Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit PrettyPrague, it triggers a privilege escalation flaw. The researcher claims to have found another zero-day in an antimalware product, this time targeting Avast Antivirus. The PoC exploits a flaw in Avast Sandbox to dump the Windows SAM database and gain a SYSTEM-level shell. It reportedly works even on fully patched Avast Antivirus and Windows 11 25H2. The researcher also suspects the flaw may affect other Gen Digital products, including AVG and Norton."
        https://securityaffairs.com/198243/hacking/chaotic-eclipse-releases-gendigital-avast-antivirus-zeroday-prettyprague.html

      Malware

      • Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
        "Huntress has identified a surge in phishing campaigns that abuse Faronics Deploy, with more than 457 endpoints encountering Faronics-related lures between July 21 and August 20. Huntress reported this activity to the Faronics support team on August 5. Starting on August 21, we observed the activity drop dramatically as they implemented new measures to disrupt threat actors. Faronics Deploy is a legitimate endpoint management platform for remotely deploying software and executing scripts across managed devices. By chaining legitimate software, attackers are leveraging Faronics to execute malicious PowerShell scripts and subsequently deploy ScreenConnect, effectively blending in with trusted business workflows. This post details the attack chain, provides key forensic artifacts such as the ScriptRunner.log, and explains how the ck identifier can be used to cluster malicious deployments and track infrastructure."
        https://www.huntress.com/blog/faronics-deploy-abuse
        https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/
        Critical Langflow Flaw Exploited To Steal OpenAI And AWS Keys*
        ***** "Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. The security issue received a critical severity rating and resides in the code validator of Langflow’s custom component editor. Threat intelligence company VulnCheck detected the activity on its honeypots in the U.K. that were targeted in at least 50 exploitation attempts over the weekend, with attack traffic originating primarily from Russia."
        https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/
        https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html
        https://www.darkreading.com/vulnerabilities-threats/critical-langflow-flaw-exploited-attacks-rise
        https://www.bankinfosecurity.com/attacks-targeting-langflow-ai-agent-building-tool-surge-a-32712
        https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/
      • Hackers Push Malicious Virtualizor Update In BGP Hijacking Attack
        "Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. Virtualizor is a legacy web control panel from Softaculous that hosting providers use to create, sell, and manage virtual private servers (VPS). An urgent notice from the vendor warns that between 20:57 UTC on August 28 and 06:10 UTC on August 30, an attacker rerouted a block of Hetzner-hosted IP addresses in a BGP (Border Gateway Protocol) hijacking attack."
        https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/
        https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
        https://www.theregister.com/security/2026/09/01/33-hour-bgp-hijack-of-softaculous-traffic-prompts-security-scramble/5293608
      • EtherHiding Exposed: What Security Leaders Need To Know
        "Attackers have compromised the websites of at least 31 legitimate businesses, including e-commerce, professional services and retail logistics organizations. Visitors arriving to the compromised sites via search engine encounter a fake “Verify you’re human”. This CAPTCHA prompt instructs them to paste a command into their own computer, a tactic known as “ClickFix”. That single action installs a persistent backdoor with no visible indication of compromise. The backdoor survives reboots, beacons to C2 every minute and retrieves updated instructions from the Polygon blockchain."
        https://www.guidepointsecurity.com/blog/etherhiding_exposed_what_security_leaders_need_to_know/
        https://www.darkreading.com/endpoint-security/clickfix-campaign-comprises-31-orgs-abuses-polygon-blockchain
      • Mirage Kitten Targeting Aviation And FinTech Sectors Across The Middle East And Africa With a New Malware Set
        "While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia. NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives."
        https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/
        https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html
        https://therecord.media/iranian-cyber-spies-target-aviation-fintech-new-malware
      • Financially Motivated Threat Actor BREEZE COMET Targets Brazil
        "Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In this blog, we detail BREEZE COMET’s tactics and toolkit, and provide mitigation recommendations and detections to support organizations in defending against this active and developing threat."
        https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/
        https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html
      • 13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
        "Socket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites that install them. The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware. We reported the iOS chain to Apple and coordinated disclosure. Apple confirmed the kernel escape was already fixed in iOS and macOS 26.1 before our report, and the two WebKit entry points are public and listed in CISA's Known Exploited Vulnerabilities catalog. Our earlier research covered six themes under a single vendor (ophimcms); this expands the confirmed set to 13 packages across five vendors and follows the chain through to the iOS payload and its most recent redeployment."
        https://socket.dev/blog/packagist-themes-ios-spyware
        https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html
      • RevStealer Is Built To Be Silent
        "RevStealer is a Windows information stealer delivered inside a trojanized Electron desktop application that impersonates legitimate software. Morphisec Threat Labs observed it distributed through GitHub repositories and game-cheat-themed sites, with the most notable lure a fake “Claude Opus 5 Free Desktop” project that impersonates Anthropic and advertises free access to a paid AI model. The theft itself is ordinary. Browser databases, session cookies, cryptocurrency wallets, password-manager artifacts and VPN configurations have been the standard infostealer haul for years. What makes RevStealer worth studying is that every stage of it is engineered around the assumption that something is watching."
        https://www.morphisec.com/blog/revstealer-silence-is-its-greatest-weapon/
        https://www.helpnetsecurity.com/2026/09/01/revstealer-malware-claude-opus-5-github/
      • FBI Raises Alarm Over Deceptive Phishing Campaign Targeting Prominent People
        "Attackers are targeting prominent, high-profile people, their family members and acquaintances on a commercial messaging application to gain long-term access to their accounts containing sensitive data, the FBI warned in an alert Tuesday. Officials did not describe the objectives or origins of the attackers, which have more recently impersonated government officials, journalists and publicly known personalities. Attackers are tricking victims into granting them access to a legitimate cloud service, such as Microsoft or Google, under the guise of reviewing a draft article or document."
        https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/
        https://www.ic3.gov/PSA/2026/PSA260901
      • Ungentlemanly Behavior: Insights Into a Ransomware Operation
        "Counter Threat Unit™ (CTU) researchers identified a consistent post-exploitation playbook used in The Gentlemen ransomware-as-a-service (RaaS) scheme, operated by a threat group that CTU™ researchers track as GOLD SHERWOOD. Rapid privilege escalation, adaptive tool usage, and aggressive defense evasion enable ransomware deployment soon after initial access, sometimes within 24 hours of the first identified post-compromise activity. The affiliates leverage legitimate tools and compromised credentials to evade detection and accelerate impact. Organizations should prioritize hardening remote access services, enforcing multi-factor authentication (MFA), monitoring administrative activity, and detecting anomalous use of data exfiltration tools and staging directories."
        https://www.sophos.com/en-us/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation

      Breaches/Hacks/Leaks

      • Aesto Health Says Data Breach Affects Over 9.5 Million Patients
        "Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. The private technology company provides software-as-a-service solutions that help healthcare organizations migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices. The company first informed the public of the attack on June 24 via a notification on its website, stating that “a limited portion” of its Amazon Web Services infrastructure had been compromised."
        https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/
        https://www.securityweek.com/9-5-million-impacted-by-aesto-health-data-breach/
        https://securityaffairs.com/198250/data-breach/attackers-access-aesto-health-aws-infrastructure-exposing-9-5-million-records.html
      • Novocure Data Breach Affects More Than 1,400 Cancer Patients
        "Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. Novocure is a global oncology company with more than 1,300 employees and operations in North America, Europe, the Middle East, and Asia, known for inventing and commercializing Tumor Treating Fields (TTFields), a non-invasive electromagnetic field therapy for cancer tumors. The Company disclosed in a filing with the U.S. Securities and Exchange Commission (SEC) that it discovered the incident after unauthorized access to some of its information systems in mid-August."
        https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/
      • AI Model Evaluator METR Hit By Credential Theft, Probing
        "A security nonprofit that helps evaluate risks in frontier AI models disclosed two cybersecurity incidents this week, including a breach that exposed an API key and a separate vulnerability that could have exposed nonpublic evaluation data. METR (Model Evaluation and Threat Research) disclosed two security incidents on Aug. 31 in which it was targeted by cyberattackers. In March of this year, attackers stole an API key used for inference on public models and consumed what METR described in a blog post as a "substantial" number of credits. In May, the company saw attackers probe publicly accessible infrastructure, including "an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.""
        https://www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing
        https://metr.org/blog/2026-08-31-security-update/
        https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html
        https://www.infosecurity-magazine.com/news/attackers-steal-metr-api-key/

      General News

      • The Guardrails Debate: Security Researcher Changes His Mind
        "Four security experts took the stage, surrounded by massive skeletons, the theme for the capture-the-flag (CTF) competition that would commence later. A panel discussion about Anthropic's Claude model compromising real-world systems was first on the agenda, but quickly turned into a broader debate on artificial intelligence (AI) guardrails. While the speakers disagreed on some fronts they aligned on one stark reality: AI capabilities are advancing at a “terrifying” pace. The battle of the bots escalated recently when frontier artificial intelligence (AI) models from OpenAI and Anthropic broke out of sandboxes during security evaluations and targeted real companies, including OpenAI's high-profile breach of Hugging Face."
        https://www.darkreading.com/cyber-risk/the-guardrails-debate-security-researcher-changes-his-mind
      • Stronger Security Drives Ransomware Groups To Recruit From Within
        "Not all breaches begin after threat actors exploit a zero-day vulnerability or launch an increasingly sophisticated phishing campaign — some start with an employee who decides to help attackers walk right through the front door. A rise in malicious insider threats reflects a good news, bad news situation: organizations are bolstering their security protocols, but cybercriminals are exploiting the one thing that firewalls and VPNs can't defend against—people with legitimate access. Incidents stemming from insider threats can result in ransomware deployment, direct financial loss, compliance violations, and full data exfiltration, just to name a few damaging outcomes."
        https://www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within
      • What Your Vendor Says About PQC Tells You If They Are Ready
        "In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity mappings, billing records and call metadata, and which becomes worthless within hours. It walks through the order of work, starting with a crypto inventory and hybrid key exchange on TLS interfaces, then IPsec links. It also names the vendor answers that should raise suspicion and explains why a missed interface is the likely point of failure."
        https://www.helpnetsecurity.com/2026/09/01/yaakov-stein-allot-telecom-pqc-migration/
      • 65% Of Enterprises Have Seen AI Agents Act Out Of Scope
        "AI agents have acted outside their intended scope at 65% of surveyed enterprises, with 29% reporting measurable organizational impact. The finding comes from Agents Without Guardrails, a research report from Enterprise Management Associates (EMA) compiled for Cequence Security and based on responses from 202 enterprise technology and security leaders. Some 46% said their organizations were already scaling agentic AI across multiple departments and production workflows, while nearly 79% were running generative and agentic AI simultaneously."
        https://www.infosecurity-magazine.com/news/65-percent-enterprises-ai-agents/
        https://www.cequence.ai/wp-content/uploads/2026/08/EMA-Research-Report-Agents-Without-Guardrails.pdf
      • Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
        "The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting for 47% of the attacks in their notifications. Nothing arrives as an attachment, so there is nothing to scan. No vulnerability is used, so there is nothing to patch."
        https://thehackernews.com/2026/09/threat-actors-dont-want-better-attacks.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) f990cce2-9ead-4995-b612-185e4520aeec-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 31 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
      • CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2e67953b-5fe2-4b2f-8ef8-4e860a80f81b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 27 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2023-49105 ownCloud Improper Authentication Vulnerability
      • CVE-2026-53362 Linux Kernel Unspecified Vulnerability
      • CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand cff6a7cf-ecba-4f28-a3fa-540b138a043a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 6 รายการลงในแคตตาล็อก

      เมื่อวันที่ 26 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 6 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
      • CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
      • CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
      • CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
      • CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability
      • CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 52405f04-6da6-4aa0-958c-23326346e0f7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 25 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-60004 Gitea Code Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 22d035de-9c97-4e00-8538-d2d8832d330c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 1 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-24-135-04 - Mitsubishi Electric Multiple FA Engineering Software Products (Update G)
      • ICSA-26-202-09 - Rockwell Automation 1734 POINT I/O (Update A)
      • ICSA-26-244-01 - Rockwell Automation RSLinx Classic
      • ICSA-26-244-02 - Rockwell Automation Redundancy Module Configuration Tool
      • ICSA-26-244-03 - Rockwell Automation Logix Platform
      • ICSA-26-244-04 - Rockwell Automation FactoryTalk Activation Manager
      • ICSA-26-244-05 - Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
      • ICSA-26-244-06 - Rockwell Automation Historian ME

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fc5c936c-a453-4930-815d-3760ffcf7181-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT