สำหรับเจ้าหน้าที่ที่ได้รับอนุญาตเท่านั้น — FOR AUTHORIZED PERSONNEL ONLY — TLP:AMBER
NCTICC-PORTAL v4.2.1  |  ● SYSTEM ONLINE  |  SESSION: UNAUTHENTICATED  |  --:-- ICT INCIDENT REPORT  |  PORTAL LOGIN  |  TLP POLICY: WHITE/AMBER/RED
ADVISORY
[26 ก.ค. 2569] APT-T18 RESURGENCE — กลุ่มที่ระบุปฏิบัติการกับ ASEAN เริ่มเปิดแคมเปญใหม่ — IOC sharing CIRCLE-3   |   [25 ก.ค. 2569] DDoS ALERT — Volumetric attack ต่อหน่วยงาน .mi.th พบจาก botnet C2 ใหม่   |   [24 ก.ค. 2569] APT ACTIVITY ELEVATED — กลุ่ม state-sponsored มุ่งเป้าโครงสร้างพื้นฐานสำคัญในภูมิภาค SEA   |   [23 ก.ค. 2569] INSIDER THREAT IOC — พบรูปแบบ data exfiltration จากภายในองค์กรกองทัพ — กำลังสืบสวน   |  
Threat Level / ระดับภัยคุกคาม
HIGH — สูง
Portal Status
OPERATIONAL
Your Session
UNAUTHENTICATED
Reports Available
8,555 (requires auth)
Last Updated
26 JUL 2569 / 14:31 ICT
INTELLIGENCE REPORTS — รายงานข่าวกรองล่าสุด TLP:RED / AMBER
รายงานเหล่านี้ต้องการการยืนยันตัวตน — Authentication required to access full reports Login →
REF # Title / หัวข้อ TLP Date Access
PB-2569-0732
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
EN · รอแปลไทย · BleepingComputer
TLP:WHITE 2026-07-26 PDF / DOCX
PB-2569-0731
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
EN · รอแปลไทย · The Hacker News
TLP:WHITE 2026-07-26 PDF / DOCX
PB-2569-0730
Malicious sites use JavaScript to build malware in browser memory
EN · รอแปลไทย · BleepingComputer
TLP:WHITE 2026-07-25 PDF / DOCX
PB-2569-0729
ShinyHunters data leaks fuel $2,000 sextortion email scam
EN · รอแปลไทย · BleepingComputer
TLP:WHITE 2026-07-25 PDF / DOCX
PB-2569-0728
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
EN · รอแปลไทย · The Hacker News
TLP:WHITE 2026-07-25 PDF / DOCX
PB-2569-0727
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
EN · รอแปลไทย · The Hacker News
TLP:WHITE 2026-07-25 PDF / DOCX
PB-2569-0726
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
EN · รอแปลไทย · The Hacker News
TLP:WHITE 2026-07-25 PDF / DOCX
PB-2569-0725
Hermes AI agent used to automate attack on Thai Finance Ministry
EN · รอแปลไทย · BleepingComputer
TLP:WHITE 2026-07-25 PDF / DOCX
PB-2569-0724
OnTrac notifies customers of data breach after network hack
EN · รอแปลไทย · BleepingComputer
TLP:WHITE 2026-07-25 PDF / DOCX
PB-2569-0723
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
EN · รอแปลไทย · BleepingComputer
TLP:WHITE 2026-07-25 PDF / DOCX
OPEN-SOURCE THREAT NEWS — ข่าวภัยคุกคามจากแหล่งเปิด TLP:WHITE
SOURCE DATE HEADLINE / หัวข้อข่าว
The Hacker News 2026-07-26 Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ↗
BleepingComputer 2026-07-25 Steam forum ClickFix attacks infect gamers with XMRig cryptominers ↗
BleepingComputer 2026-07-25 Malicious sites use JavaScript to build malware in browser memory ↗
The Hacker News 2026-07-25 Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available ↗
SANS ISC 2026-07-24 ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) ↗
CISA 2026-07-23 Weintek cMT3092X ↗
CISA 2026-07-23 Rockwell Automation ThinManager ↗
NCSC.gov.uk 2026-07-23 UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations ↗
SANS ISC 2026-07-23 When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd) ↗
NCSC.gov.uk 2026-07-22 Post-quantum cryptography (PQC) migration workshop report ↗
KrebsOnSecurity 2026-07-22 LG to Ban Residential Proxies from Smart TV Apps ↗
JPCERT/CC 2026-07-15 Security Alert: Microsoft Releases July 2026 Security Updates ↗
Aggregated from CISA, SANS ISC, US-CERT, NCSC.gov.uk · refreshed every 30 minutes · links open in new tab on the original publisher site
ABOUT NCTICC — เกี่ยวกับ ศปข. TLP:WHITE
ศูนย์ประสานงานข่าวกรองภัยคุกคามไซเบอร์แห่งชาติ (ศปข.) คือศูนย์กลางการแบ่งปันและประสานงานข่าวกรองภัยคุกคามทางไซเบอร์ระหว่างหน่วยงานภาครัฐ กองทัพ และองค์กรโครงสร้างพื้นฐานสำคัญของประเทศไทย จัดตั้งภายใต้ พ.ร.บ. การรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. 2562
The National Cyber Threat Intelligence Coordination Center (NCTICC) serves as Thailand's central platform for cyber threat intelligence sharing and coordination among government agencies, military commands, and critical infrastructure operators, operating under the Cybersecurity Act B.E. 2562.
THREAT ASSESSMENT ระดับภัยคุกคาม
CRITICAL วิกฤต — Imminent attack
HIGH ◄ สูง — APT activity elevated
CURRENT LEVEL
ELEVATED ยกระดับ — Significant risk
GUARDED เฝ้าระวัง — General risk
LOW ต่ำ — Routine
ASSESSED: 26 JUL 2569 / 14:31 ICT
NEXT REVIEW: 27 ก.ค. 2569
→ Full assessment (auth required)
MEMBER AGENCIES 47 หน่วยงาน
ACC กองบัญชาการไซเบอร์ ทบ.
Army Cyber Command
ACTIVE
NCOC ศูนย์ปฏิบัติการไซเบอร์ ทร.
Naval Cyber Ops Ctr.
ACTIVE
AFCIU หน่วยข่าวกรองไซเบอร์ ทอ.
Air Force Cyber Intel
ACTIVE
NIA สำนักข่าวกรองแห่งชาติ
Natl. Intelligence Agency
ACTIVE
NCSA สำนักงาน สกมช.
Cyber Security Agency
ACTIVE
CCIB บก.สืบสวนไซเบอร์ สตช.
Cyber Crime Bureau
ACTIVE
PORTAL ACCESS RESTRICTED
เข้าสู่ระบบเพื่อเข้าถึงรายงานข่าวกรอง
TLP:RED / AMBER และ IOC Database
Secure Portal Login →
Unauthorized access is monitored
and subject to legal action under
Cybersecurity Act B.E. 2562