<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://www.dekhub.net/feed.xml" rel="self" type="application/atom+xml" /><link href="https://www.dekhub.net/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-07-12T07:09:45+00:00</updated><id>https://www.dekhub.net/feed.xml</id><title type="html">The Daily Take</title><subtitle>Daily dispatches on whatever&apos;s genuinely trending — tech, security, money, tools, the occasional trainwreck — fact-checked against primary sources, by someone who&apos;s actually run the infrastructure. No recycled listicles, no generic &quot;best products&quot; filler.</subtitle><author><name>Arthur Reed</name></author><entry><title type="html">Progress Software Buys a Second File-Transfer Company. It Also Gets Hacked.</title><link href="https://www.dekhub.net/2026/07/12/progress-sharefile-groundhog-day/" rel="alternate" type="text/html" title="Progress Software Buys a Second File-Transfer Company. It Also Gets Hacked." /><published>2026-07-12T00:00:00+00:00</published><updated>2026-07-12T00:00:00+00:00</updated><id>https://www.dekhub.net/2026/07/12/progress-sharefile-groundhog-day</id><content type="html" xml:base="https://www.dekhub.net/2026/07/12/progress-sharefile-groundhog-day/"><![CDATA[<p>Progress Software spent 2023 living down MOVEit — the file-transfer tool whose zero-day let the Clop ransomware gang rifle through more than 2,700 organizations and roughly 46 million people’s data, in what’s still one of the ugliest breach years on record. So in October 2024, Progress paid $875 million to acquire ShareFile, the old Citrix-born file-sharing platform, explicitly to diversify its file-transfer portfolio beyond MOVEit’s tarnished name.</p>

<p>Fast forward to July 10, 2026: ShareFile customers got an email telling them to physically shut down the Windows servers running their Storage Zone Controllers, immediately, because Progress had identified a “credible external security threat.” No CVE. No patch. No real explanation beyond “trust us, unplug it” — an email that leaked to Reddit’s r/sysadmin before Progress said a public word about it.</p>

<p>This isn’t even ShareFile’s first rodeo this year. Back in March, Progress quietly patched a pre-auth remote code execution chain in those same Storage Zone Controllers — CVE-2026-2699 and CVE-2026-2701, a CVSS 9.8 authentication bypass chained to a 9.1 RCE, found by watchTowr Labs. The bug was almost insultingly simple: one bad boolean in a .NET redirect kept an admin panel rendering after it should have booted the visitor out, and from there an attacker could smuggle a webshell into the webroot disguised as a legitimate file upload — no login required. watchTowr counted roughly 30,000 of these boxes exposed directly to the public internet.</p>

<p>So: buy a second file-transfer vendor to escape the reputational shadow of the first one’s catastrophic breach, and four months after patching one critical flaw in it, send customers a second “please turn off your file server, we won’t say why” email in the same year. If Progress Software were a stock, you’d short it on symbolism alone.</p>

<p>To be fair, Progress is handling this one better than MOVEit — disabling access and shutting things down before confirming any actual compromise, rather than after. That’s the right instinct. But if you’re an admin who’s now had two “kill your file server” emails from the same vendor in twelve months, the conversation stops being “patch and monitor” and starts being “why does this vendor still hold our clients’ contracts and payroll files.”</p>

<p>The practical takeaway for anyone moving sensitive files through third-party platforms, SaaS or on-prem, isn’t “panic-switch vendors.” It’s that your own credential hygiene is the one layer you actually control when the vendor’s isn’t holding. If admin logins, client portals, or shared drives are sitting behind reused or weak passwords, a vendor’s bad week becomes your bad week too.</p>

<div class="cta-box">
<span class="tag">Worth trying</span>
<p>If today's story has you thinking about your own password hygiene rather than your vendor's, <strong>1Password</strong>'s Watchtower feature flags reused, weak, and breached-site passwords automatically — the one control you actually have when a vendor's security doesn't hold.</p>
</div>

<p>Sources: <a href="https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/">BleepingComputer</a>, <a href="https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html">The Hacker News</a>, <a href="https://www.techtimes.com/articles/320148/20260711/progress-pulls-sharefile-storage-zone-controllers-offline-no-patch-available.htm">Tech Times</a>, <a href="https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/">watchTowr Labs</a>, <a href="https://techcrunch.com/2024/09/09/progress-acquires-file-management-platform-sharefile-for-875m/">TechCrunch</a>, <a href="https://www.techzine.eu/news/collaboration/124207/progress-buys-old-citrix-service-sharefile-with-an-eye-on-moveit/">Techzine</a></p>]]></content><author><name>Arthur Reed</name></author><category term="security" /><category term="saas" /><summary type="html"><![CDATA[Progress bought ShareFile to escape MOVEit's shadow. Four months after patching one critical flaw in it, they're telling customers to unplug it over a second unexplained threat.]]></summary></entry><entry><title type="html">Your AI Coding Assistant Will Happily Install Malware It Just Made Up</title><link href="https://www.dekhub.net/2026/07/11/hallusquatting-ai-coding-assistants/" rel="alternate" type="text/html" title="Your AI Coding Assistant Will Happily Install Malware It Just Made Up" /><published>2026-07-11T00:00:00+00:00</published><updated>2026-07-11T00:00:00+00:00</updated><id>https://www.dekhub.net/2026/07/11/hallusquatting-ai-coding-assistants</id><content type="html" xml:base="https://www.dekhub.net/2026/07/11/hallusquatting-ai-coding-assistants/"><![CDATA[<div class="lang-en">

  <p>There’s a very specific flavor of dumb in cybersecurity right now, and it belongs to your AI coding assistant. Researchers from Tel Aviv University, Technion, and Intuit just published an attack called “HalluSquatting,” and the mechanism is almost insultingly simple: your coding agent hallucinates a package or repo name that doesn’t exist, and an attacker who saw that coming has already registered it — stuffed with malware.</p>

  <p>Here’s how it plays out. Ask Cursor, GitHub Copilot, Windsurf, Cline, Gemini CLI, or OpenClaw to clone a repo or install a “skill,” and these tools will sometimes confidently invent a name that sounds plausible but was never real — the same species of confabulation as an AI citing a court case that doesn’t exist. Normally that’s just an annoying wrong answer. But an attacker who’s been probing the same models can predict which fake names they’re likely to dream up, register those names for real on GitHub or npm ahead of time, and load them with a payload. When your assistant hallucinates the name and pulls it down through its own terminal access, it doesn’t just suggest bad code — it executes the attacker’s commands directly, no click required from you.</p>

  <blockquote>
    <p>Traditional botnets spread through weak passwords and unpatched boxes. This one spreads through your coding assistant’s imagination.</p>
  </blockquote>

  <p>The numbers are the part that should actually worry you: the researchers measured hallucination rates up to 85% in repo-cloning tasks and up to 100% in certain skill-installation scenarios. That’s not an edge case — that’s the median outcome for entire categories of prompts. And because the exploit rides in through the model’s own hallucination rather than a phishing link or malicious attachment, it slides past every defense built for how humans get owned, not how AI agents do.</p>

  <p>The uncomfortable subtext is that this isn’t a bug you patch — it’s the tradeoff of giving an LLM a terminal and telling it to be fast and helpful. Every “agentic coding” pitch of the last two years has been “let it just do the thing,” and this is what “just do the thing” looks like when the thing it does is invent a URL and then trust it.</p>

  <p>None of this means throw your Cursor subscription in the bin. It means the same discipline that used to apply to random npm installs off Stack Overflow now applies to whatever your AI just typed into a terminal on your behalf — check what actually got pulled down before you run it, and put something between the agent and blind execution that actually inspects the package instead of trusting the vibes.</p>

  <div class="cta-box">
<span class="tag">Worth trying</span>
<p>The direct defense here isn't "trust the AI less" — it's putting an automated check between your coding agent and its terminal. Aikido Security's code-to-runtime platform (SAST, SCA, and supply-chain scanning) is built to catch exactly this: a newly-registered, suspicious package flagged before it executes, not after.</p>
</div>

  <p>Good week to actually read what your AI just installed.</p>

</div>

<div class="lang-th" lang="th">

  <p>มีความโง่แบบเฉพาะทางที่กำลังเกิดขึ้นในวงการความปลอดภัยไซเบอร์ตอนนี้ และมันเป็นของ AI coding assistant ของคุณเอง นักวิจัยจาก Tel Aviv University, Technion และ Intuit เพิ่งเผยแพร่การโจมตีที่ชื่อว่า “HalluSquatting” และกลไกของมันง่ายจนแทบจะดูถูกสติปัญญา คือ AI ผู้ช่วยเขียนโค้ดของคุณ “หลอน” (hallucinate) ชื่อแพ็กเกจหรือรีโพที่ไม่มีอยู่จริงขึ้นมา แล้วแฮกเกอร์ที่คาดเดาไว้ล่วงหน้าก็จดทะเบียนชื่อนั้นไว้แล้ว พร้อมยัดมัลแวร์เข้าไปเรียบร้อย</p>

  <p>กลไกเป็นแบบนี้ ลองสั่งให้ Cursor, GitHub Copilot, Windsurf, Cline, Gemini CLI หรือ OpenClaw โคลนรีโพหรือติดตั้ง “skill” ดู เครื่องมือเหล่านี้บางครั้งจะมั่นใจสุด ๆ ในการสร้างชื่อที่ฟังดูสมเหตุสมผลแต่ไม่เคยมีอยู่จริงขึ้นมา เป็นอาการเดียวกับที่ AI อ้างอิงคดีความในศาลที่ไม่มีอยู่จริง ปกติแล้วมันก็แค่คำตอบผิดที่น่ารำคาญ แต่แฮกเกอร์ที่คอยสังเกตโมเดลเดียวกันสามารถคาดเดาได้ว่าชื่อปลอมแบบไหนที่ AI มักจะ “ฝัน” ขึ้นมา แล้วไปจดทะเบียนชื่อเหล่านั้นจริง ๆ บน GitHub หรือ npm ไว้ล่วงหน้า พร้อมใส่เพย์โหลดอันตรายเข้าไป เมื่อผู้ช่วย AI ของคุณหลอนชื่อนั้นขึ้นมาแล้วดึงมันลงมาผ่านเทอร์มินัลของตัวเอง มันไม่ได้แค่แนะนำโค้ดแย่ ๆ เท่านั้น แต่มันรันคำสั่งของแฮกเกอร์โดยตรง ไม่ต้องมีการคลิกใด ๆ จากคุณเลย</p>

  <blockquote>
    <p>บอตเน็ตแบบดั้งเดิมแพร่กระจายผ่านรหัสผ่านที่อ่อนแอและเครื่องที่ไม่ได้แพตช์ แต่ตัวนี้แพร่กระจายผ่านจินตนาการของผู้ช่วยเขียนโค้ด AI ของคุณเอง</p>
  </blockquote>

  <p>ตัวเลขคือส่วนที่ควรทำให้คุณกังวลจริง ๆ นักวิจัยวัดอัตราการหลอนได้สูงถึง 85% ในงานโคลนรีโพ และสูงถึง 100% ในบางสถานการณ์การติดตั้ง skill นี่ไม่ใช่กรณีขอบ ๆ แต่เป็นผลลัพธ์ปกติของพรอมป์ทั้งหมวดหมู่ และเพราะการโจมตีนี้อาศัยอาการหลอนของโมเดลเอง ไม่ใช่ลิงก์ฟิชชิงหรือไฟล์แนบอันตราย มันจึงหลบเลี่ยงการป้องกันที่ถูกออกแบบมาสำหรับวิธีที่มนุษย์โดนหลอก ไม่ใช่วิธีที่ AI agent โดนหลอก</p>

  <p>ประเด็นที่น่าอึดอัดคือ นี่ไม่ใช่บั๊กที่แพตช์ได้ แต่เป็นข้อแลกเปลี่ยนของการให้ LLM เข้าถึงเทอร์มินัลแล้วบอกให้มันช่วยเหลือแบบรวดเร็ว ทุกการขายไอเดีย “agentic coding” ในช่วงสองปีที่ผ่านมาคือ “ปล่อยให้มันทำเองเลย” และนี่แหละคือหน้าตาของ “ปล่อยให้มันทำเองเลย” เมื่อสิ่งที่มันทำคือการสร้าง URL ขึ้นมาเองแล้วก็เชื่อมัน</p>

  <p>ทั้งหมดนี้ไม่ได้แปลว่าให้เลิกใช้ Cursor แต่แปลว่าวินัยแบบเดียวกับที่เคยใช้กับการติดตั้ง npm สุ่ม ๆ จาก Stack Overflow ตอนนี้ต้องใช้กับสิ่งที่ AI ของคุณเพิ่งพิมพ์ลงเทอร์มินัลแทนคุณด้วย ตรวจสอบว่าอะไรถูกดึงลงมาจริง ๆ ก่อนรัน และวางบางอย่างไว้ระหว่าง agent กับการรันแบบไม่ตรวจสอบ ที่ตรวจดูแพ็กเกจจริง ๆ แทนที่จะเชื่อความรู้สึก</p>

  <div class="cta-box">
<span class="tag">น่าลองใช้</span>
<p>ทางป้องกันโดยตรงตรงนี้ไม่ใช่ "เชื่อ AI น้อยลง" แต่คือการวางระบบตรวจสอบอัตโนมัติไว้ระหว่าง coding agent กับเทอร์มินัลของมัน แพลตฟอร์ม code-to-runtime ของ Aikido Security (SAST, SCA และการสแกน supply-chain) ถูกสร้างมาเพื่อจับสิ่งนี้โดยเฉพาะ คือแพ็กเกจที่เพิ่งจดทะเบียนใหม่และน่าสงสัยจะถูกตรวจพบก่อนที่มันจะถูกรัน ไม่ใช่หลังจากนั้น</p>
</div>

  <p>สัปดาห์นี้เหมาะเป็นอย่างยิ่งที่จะลองอ่านจริง ๆ ว่า AI ของคุณเพิ่งติดตั้งอะไรลงไป</p>

</div>

<p><span class="lang-en"><strong>Sources:</strong></span><span class="lang-th" lang="th"><strong>แหล่งข้อมูล:</strong></span> <a href="https://www.securityweek.com/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/">SecurityWeek</a>, <a href="https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.html">The Hacker News</a>, <a href="https://decrypt.co/373196/ai-agents-botnets-hallucinations-researchers-warn">Decrypt</a>, <a href="https://www.scworld.com/brief/hallusquatting-new-ai-attack-method-enables-scalable-botnets-and-large-scale-infections">SC Media</a></p>]]></content><author><name>Arthur Reed</name></author><category term="ai" /><category term="security" /><category term="dev-tools" /><summary type="html"><![CDATA[Researchers just showed Cursor, Copilot, Windsurf and friends can be tricked into cloning malware-laden repos they hallucinated themselves — hallucination rates up to 100% for some prompts.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.dekhub.net/assets/images/posts/2026-07-11-hallusquatting.jpg" /><media:content medium="image" url="https://www.dekhub.net/assets/images/posts/2026-07-11-hallusquatting.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Ubiquiti’s UniFi Just Scored a Perfect 10 (That’s Bad)</title><link href="https://www.dekhub.net/2026/07/10/ubiquiti-unifi-perfect-ten/" rel="alternate" type="text/html" title="Ubiquiti’s UniFi Just Scored a Perfect 10 (That’s Bad)" /><published>2026-07-10T00:00:00+00:00</published><updated>2026-07-10T00:00:00+00:00</updated><id>https://www.dekhub.net/2026/07/10/ubiquiti-unifi-perfect-ten</id><content type="html" xml:base="https://www.dekhub.net/2026/07/10/ubiquiti-unifi-perfect-ten/"><![CDATA[<div class="lang-en">

  <p>Ubiquiti’s UniFi lineup built its entire reputation on one promise: enterprise-grade networking gear that a single IT person (or a broadcast engineer moonlighting as network admin) can manage from a slick app, from anywhere, without a six-figure Cisco support contract. That promise is also, this week, the reason roughly 100,000 UniFi devices are sitting on the open internet with a target on their backs.</p>

  <p>On July 8, Ubiquiti shipped Security Advisory Bulletin 066, patching seven critical flaws spread across UniFi Connect, Talk, Access, Protect, and OS. The headline item, CVE-2026-50746, scores a flawless 10.0 on the CVSS scale — the vulnerability equivalent of a perfect judges’ score, except the routine is “unauthenticated attacker sends one crafted request and gets arbitrary command execution on your building’s access control and lighting controller.” No login required, no user interaction. Six more flaws in the same bulletin sit in the 9.0–9.9 range, touching UniFi Talk’s phone system, UniFi Access’s door controllers, and UniFi Protect’s video feeds via an SSRF chain.</p>

  <blockquote>
    <p>Point the controller at the world, manage it from your phone, never think about it again — until someone else does the thinking for you.</p>
  </blockquote>

  <p>The kicker: threat intel firm Censys puts roughly 100,000 UniFi OS endpoints reachable straight from the public internet right now — which is precisely the deployment pattern UniFi’s whole pitch encourages. Ubiquiti says there’s no evidence these seven are being actively exploited yet, but a different trio of UniFi OS bugs was already flagged by CISA as weaponized in real-world attacks just last month. And Ubiquiti gear has history here: Russian state-sponsored hackers ran the MooBot botnet off compromised Ubiquiti EdgeOS routers for years before a 2024 law enforcement takedown finally killed it.</p>

  <p>None of this makes UniFi bad gear. It makes it exactly what it’s always been: brilliant hardware wrapped in a management philosophy that assumes the internet is friendlier than it is. If you’re running UniFi Connect, Access, Protect, or Talk — and if you’ve got a studio, small office, or rental property with a Ubiquiti controller in a closet somewhere, you probably are — patch to the fixed builds today (Connect 3.4.20, Talk 5.2.2, Access 4.2.29, Protect 7.1.83, OS 5.1.19) and then ask the harder question: why does that controller have a public IP at all?</p>

  <p>For most small deployments, the honest answer is: it doesn’t need one. The controller should sit behind a private, authenticated access layer that only your team can reach — not the entire internet plus whoever’s scanning Shodan and Censys this week.</p>

  <div class="cta-box">
<span class="tag">Worth trying</span>
<p>The fix here isn't a firewall rule you'll forget about — it's putting management interfaces behind a proper private network layer instead of a raw public IP. NordLayer (Nord Security's business VPN / Zero Trust access product) is built for exactly this: your controller stays reachable to your team and invisible to everyone else scanning the internet.</p>
</div>

</div>

<div class="lang-th" lang="th">

  <p>ชื่อเสียงทั้งหมดของ UniFi จาก Ubiquiti สร้างขึ้นจากคำมั่นสัญญาเดียว คืออุปกรณ์เครือข่ายระดับองค์กรที่คนไอทีคนเดียว (หรือวิศวกรออกอากาศที่รับหน้าที่ดูแลเครือข่ายไปด้วย) สามารถจัดการได้จากแอปสวย ๆ จากที่ไหนก็ได้ โดยไม่ต้องเสียค่าซัพพอร์ต Cisco หลักแสน คำมั่นสัญญานั้นเองก็เป็นเหตุผลที่สัปดาห์นี้อุปกรณ์ UniFi ราว 100,000 เครื่องกำลังเปิดโล่งอยู่บนอินเทอร์เน็ตพร้อมเป็นเป้าโจมตี</p>

  <p>เมื่อวันที่ 8 กรกฎาคม Ubiquiti ออก Security Advisory Bulletin 066 แพตช์ช่องโหว่ระดับวิกฤต 7 รายการ ครอบคลุม UniFi Connect, Talk, Access, Protect และ OS ตัวเด่นคือ CVE-2026-50746 ที่ได้คะแนนเต็ม 10.0 บนสเกล CVSS ซึ่งเทียบเท่ากับคะแนนเต็มจากกรรมการ เพียงแต่ท่าที่แสดงคือ “ผู้โจมตีที่ไม่ต้องล็อกอินส่งคำขอที่สร้างขึ้นมาเพียงครั้งเดียว ก็สามารถรันคำสั่งใด ๆ บนตัวควบคุมระบบควบคุมการเข้าออกและระบบไฟส่องสว่างของอาคารได้ทันที” ไม่ต้องล็อกอิน ไม่ต้องให้ผู้ใช้ทำอะไรเลย ช่องโหว่อีก 6 รายการในบูลเลตินเดียวกันอยู่ในช่วง 9.0–9.9 กระทบทั้งระบบโทรศัพท์ของ UniFi Talk ตัวควบคุมประตูของ UniFi Access และฟีดวิดีโอของ UniFi Protect ผ่านช่องโหว่ SSRF</p>

  <blockquote>
    <p>ชี้ตัวควบคุมออกสู่โลกภายนอก จัดการมันผ่านมือถือ แล้วไม่ต้องคิดถึงมันอีกเลย — จนกว่าจะมีคนอื่นคิดแทนคุณ</p>
  </blockquote>

  <p>ประเด็นสำคัญคือ บริษัทข่าวกรองภัยคุกคาม Censys ระบุว่าตอนนี้มีเอนด์พอยต์ UniFi OS ราว 100,000 เครื่องที่เข้าถึงได้โดยตรงจากอินเทอร์เน็ตสาธารณะ ซึ่งเป็นรูปแบบการติดตั้งที่แนวทางการขายของ UniFi สนับสนุนพอดี Ubiquiti ระบุว่ายังไม่มีหลักฐานว่าช่องโหว่ทั้ง 7 นี้ถูกใช้โจมตีจริง แต่ก่อนหน้านี้เมื่อเดือนที่แล้ว CISA เคยแจ้งเตือนว่าช่องโหว่อีกชุดหนึ่งใน UniFi OS ถูกนำไปใช้โจมตีจริงแล้ว และอุปกรณ์ Ubiquiti ก็มีประวัติในเรื่องนี้ แฮกเกอร์ที่ได้รับการสนับสนุนจากรัฐบาลรัสเซียเคยใช้เราเตอร์ Ubiquiti EdgeOS ที่ถูกแฮ็กเพื่อรันบอตเน็ต MooBot อยู่หลายปี ก่อนจะถูกปราบปรามโดยหน่วยงานบังคับใช้กฎหมายในปี 2024</p>

  <p>เรื่องนี้ไม่ได้แปลว่า UniFi เป็นอุปกรณ์ที่แย่ มันแค่เป็นสิ่งที่มันเป็นมาตลอด คือฮาร์ดแวร์ที่ยอดเยี่ยมห่อหุ้มด้วยแนวคิดการจัดการที่สมมติว่าอินเทอร์เน็ตเป็นมิตรมากกว่าความเป็นจริง ถ้าคุณใช้งาน UniFi Connect, Access, Protect หรือ Talk อยู่ — และถ้าคุณมีสตูดิโอ ออฟฟิศเล็ก ๆ หรือบ้านเช่าที่มีตัวควบคุม Ubiquiti ซ่อนอยู่ในตู้สักที่หนึ่ง คุณก็น่าจะใช้อยู่ — ให้อัปเดตเป็นเวอร์ชันที่แก้ไขแล้ววันนี้เลย (Connect 3.4.20, Talk 5.2.2, Access 4.2.29, Protect 7.1.83, OS 5.1.19) แล้วค่อยถามคำถามที่ยากกว่า คือทำไมตัวควบคุมนั้นถึงต้องมี public IP ตั้งแต่แรก</p>

  <p>สำหรับการติดตั้งขนาดเล็กส่วนใหญ่ คำตอบที่ตรงไปตรงมาคือ ไม่จำเป็นเลย ตัวควบคุมควรอยู่หลังชั้นการเข้าถึงแบบส่วนตัวที่ต้องยืนยันตัวตน ซึ่งมีแค่ทีมของคุณเท่านั้นที่เข้าถึงได้ ไม่ใช่อินเทอร์เน็ตทั้งหมดบวกกับใครก็ตามที่กำลังสแกน Shodan และ Censys อยู่สัปดาห์นี้</p>

  <div class="cta-box">
<span class="tag">น่าลองใช้</span>
<p>ทางแก้ตรงนี้ไม่ใช่กฎไฟร์วอลล์ที่คุณจะลืมไปในที่สุด แต่คือการเอาอินเทอร์เฟซการจัดการไปไว้หลังชั้นเครือข่ายส่วนตัวที่เหมาะสม แทนที่จะเปิด public IP โล่ง ๆ NordLayer (ผลิตภัณฑ์ VPN / Zero Trust สำหรับธุรกิจของ Nord Security) ถูกสร้างมาเพื่อสิ่งนี้โดยเฉพาะ ตัวควบคุมของคุณยังเข้าถึงได้สำหรับทีม แต่มองไม่เห็นสำหรับคนอื่นที่กำลังสแกนอินเทอร์เน็ตอยู่</p>
</div>

</div>

<p><span class="lang-en"><strong>Sources:</strong></span><span class="lang-th" lang="th"><strong>แหล่งข้อมูล:</strong></span> <a href="https://thehackernews.com/2026/07/ubiquiti-patches-critical-unifi-flaws.html">The Hacker News</a>, <a href="https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc">Ubiquiti Security Advisory Bulletin 066</a>, <a href="https://www.techtimes.com/articles/319919/20260708/unifi-cvss-100-flaw-exposes-100000-endpoints-unauthenticated-takeover.htm">Tech Times</a>, <a href="https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/">BleepingComputer</a></p>]]></content><author><name>Arthur Reed</name></author><category term="security" /><category term="networking" /><category term="iot" /><summary type="html"><![CDATA[Ubiquiti patched seven critical UniFi flaws this week, including a flawless CVSS 10.0 unauthenticated command injection bug — and roughly 100,000 UniFi endpoints are sitting exposed on the public internet right now.]]></summary></entry><entry><title type="html">The Shy Guitarist Who Turned Into a Rock Star: Nene Royal’s Zombie Audition</title><link href="https://www.dekhub.net/2026/07/09/nene-royal-agt-zombie-audition/" rel="alternate" type="text/html" title="The Shy Guitarist Who Turned Into a Rock Star: Nene Royal’s Zombie Audition" /><published>2026-07-09T00:00:00+00:00</published><updated>2026-07-09T00:00:00+00:00</updated><id>https://www.dekhub.net/2026/07/09/nene-royal-agt-zombie-audition</id><content type="html" xml:base="https://www.dekhub.net/2026/07/09/nene-royal-agt-zombie-audition/"><![CDATA[<div class="lang-en">

  <p>One day before her 16th birthday, a soft-spoken teenager from Phuket, Thailand walked onto the <em>America’s Got Talent</em> stage looking every bit as nervous as any first-time contestant. Ninety seconds later, she was growling out The Cranberries’ “Zombie” with an electric guitar slung over her shoulder, and the room had completely flipped.</p>

  <p>Nene Royal’s audition, which aired July 7 as part of AGT’s 21st season, has since become one of the most shared clips of the season — and for good reason. It’s a study in contrast: a quiet kid with an oversized dream, and a performer who commands a stage like she’s done it a thousand times.</p>

  <p><strong>The setup.</strong> Royal told the judging panel she’d been playing guitar since age seven and that her “biggest dream is that I really want to be a superstar on tour.” It was, by her own admission, the biggest stage she’d ever played. Her father stood at the side of the stage for support as she readied her guitar — a small, human detail that made the transformation that followed land even harder.</p>

  <p><strong>The performance.</strong> Rather than reach for a pop ballad or a run of vocal acrobatics — the safe choices most 16-year-old contestants make — Royal went for something riskier: a gritty, fully rocked-up cover of The Cranberries’ 1994 alt-rock landmark “Zombie.” She opened with a roaring guitar slide and nimble fretwork, then unleashed a guttural growl before pulling back into the song’s more melodic core, channeling Dolores O’Riordan’s full range — tender one moment, ferocious the next. By the final chorus she had the crowd, and several judges, singing along.</p>

  <p>All four judges voted yes.</p>

  <blockquote>
    <p>“That was spectacular. You have a really good chance to do very good in this competition.” — Sofía Vergara</p>

    <p>“You are such a surprise with the energy and the rock and roll. You are a rock star, young lady. You really are.” — Howie Mandel</p>

    <p>“You’ve got really good vocal control and you can kill it on the guitar. You’re like a match made in heaven. You’re brilliant.” — Mel B</p>

    <p>“The tone of your voice is like really authentic. Even the fact that it was all a bit messy made the audition for me really good.” — Simon Cowell</p>
  </blockquote>

  <p>After the four yeses, Royal reverted right back to her shy, nervous-smile self as she exited the stage — the same contrast that opened the audition, played in reverse.</p>

  <p><strong>Who is Nene Royal?</strong> She’s largely self-taught, having picked up guitar by ear watching online videos. Her competitive résumé already includes a second-place finish in Thailand’s Overdrive Guitar Contest (The Guitar Battle) in 2023 and an Outstanding Player award at the King Power Band Competition in September 2025. She’s also a Featured Artist with Enya Music, plays regular weekend shows in Phuket, and is working on material for a debut EP. Her online following has already passed 3 million across platforms.</p>

  <p>Her audition also landed at a fitting moment for the song itself: The Cranberries recently announced their first-ever live album, <em>Live at London Astoria II, 1994</em>, arriving August 28 — a reminder that “Zombie” is still finding new audiences, three decades and one AGT stage later.</p>

</div>

<div class="lang-th" lang="th">

  <p>หนึ่งวันก่อนวันเกิดอายุครบ 16 ปี วัยรุ่นสาวพูดจาแผ่วเบาจากภูเก็ต ประเทศไทย ก้าวขึ้นเวที <em>America’s Got Talent</em> ด้วยท่าทีตื่นเต้นไม่ต่างจากผู้เข้าแข่งขันหน้าใหม่คนอื่น ๆ แต่เก้าสิบวินาทีต่อมา เธอกำลังคำรามร้องเพลง “Zombie” ของ The Cranberries พร้อมกีตาร์ไฟฟ้าคล้องบ่า และทั้งห้องก็พลิกกลับหน้ามือเป็นหลังมือทันที</p>

  <p>การออดิชั่นของเนเน่ รอยัล ซึ่งออกอากาศเมื่อวันที่ 7 กรกฎาคม ในซีซั่นที่ 21 ของ AGT กลายเป็นหนึ่งในคลิปที่ถูกแชร์มากที่สุดของซีซั่นนี้ — และก็สมเหตุสมผล มันคือความขัดแย้งที่ลงตัว: เด็กสาวเงียบขรึมกับความฝันที่ใหญ่เกินตัว และนักแสดงที่ครองเวทีราวกับทำแบบนี้มาแล้วนับพันครั้ง</p>

  <p><strong>การเปิดตัว</strong> เนเน่บอกคณะกรรมการว่าเธอเล่นกีตาร์มาตั้งแต่อายุ 7 ขวบ และ “ความฝันที่ยิ่งใหญ่ที่สุดคืออยากเป็นซูเปอร์สตาร์ที่ทัวร์คอนเสิร์ตทั่วโลก” เธอยอมรับว่านี่คือเวทีที่ใหญ่ที่สุดที่เธอเคยเล่น พ่อของเธอยืนอยู่ข้างเวทีคอยให้กำลังใจขณะที่เธอเตรียมกีตาร์ — รายละเอียดเล็ก ๆ ที่ทำให้การเปลี่ยนแปลงที่ตามมายิ่งทรงพลังมากขึ้น</p>

  <p><strong>การแสดง</strong> แทนที่จะเลือกเพลงป็อปบัลลาดหรือโชว์เทคนิคเสียงร้องแบบปลอดภัย ซึ่งเป็นทางเลือกทั่วไปของผู้เข้าแข่งขันวัย 16 ปี เนเน่กลับเลือกสิ่งที่เสี่ยงกว่า นั่นคือคัฟเวอร์เพลงร็อคระดับตำนานยุค 90 อย่าง “Zombie” ของ The Cranberries (ปี 1994) แบบเต็มพลัง เธอเปิดการแสดงด้วยการรูดกีตาร์เสียงคำรามและการดีดสายที่คล่องแคล่ว ก่อนจะปล่อยเสียงคำรามจากลำคอ แล้วดึงกลับสู่ท่วงทำนองที่นุ่มนวลกว่าของเพลง ถ่ายทอดช่วงเสียงเต็มรูปแบบของ Dolores O’Riordan — อ่อนโยนในบางจังหวะ ดุดันในอีกจังหวะหนึ่ง เมื่อถึงท่อนฮุกสุดท้าย เธอทำให้ผู้ชมและกรรมการหลายคนร้องตามไปด้วย</p>

  <p>กรรมการทั้งสี่คนโหวตผ่านทั้งหมด</p>

  <blockquote>
    <p>“มันยอดเยี่ยมมาก คุณมีโอกาสที่ดีมากที่จะไปได้ไกลในการแข่งขันนี้” — Sofía Vergara</p>

    <p>“คุณคือความประหลาดใจด้วยพลังงานและความร็อคแอนด์โรล คุณคือร็อคสตาร์ตัวจริง สาวน้อย” — Howie Mandel</p>

    <p>“คุณควบคุมเสียงร้องได้ดีมาก และเล่นกีตาร์ได้อย่างเจ๋งสุด ๆ คุณเป็นเหมือนคู่ที่ถูกสร้างมาคู่กัน คุณยอดเยี่ยมมาก” — Mel B</p>

    <p>“โทนเสียงของคุณแท้จริงมาก ถึงแม้จะดูรุงรังไปบ้าง แต่นั่นแหละที่ทำให้การออดิชั่นนี้ดีมากสำหรับผม” — Simon Cowell</p>
  </blockquote>

  <p>หลังจากได้รับเสียงโหวตผ่านทั้งสี่เสียง เนเน่ก็กลับไปเป็นเด็กสาวขี้อายยิ้มแบบเขินอายอีกครั้งขณะเดินลงจากเวที — ความขัดแย้งเดียวกับตอนเปิดการแสดง เพียงแต่สลับด้าน</p>

  <p><strong>เนเน่ รอยัล คือใคร?</strong> เธอเรียนกีตาร์ด้วยตัวเองเป็นส่วนใหญ่ โดยฟังและดูวิดีโอออนไลน์ ประวัติการแข่งขันของเธอรวมถึงรางวัลรองชนะเลิศอันดับ 1 ในรายการ Overdrive Guitar Contest (The Guitar Battle) ของประเทศไทยเมื่อปี 2023 และรางวัล Outstanding Player จากการแข่งขัน King Power Band Competition เมื่อเดือนกันยายน 2025 เธอยังเป็นศิลปินในสังกัด Enya Music เล่นโชว์สดที่ภูเก็ตทุกสุดสัปดาห์ และกำลังเตรียมผลงาน EP เปิดตัว ผู้ติดตามออนไลน์ของเธอมีมากกว่า 3 ล้านคนแล้วในทุกแพลตฟอร์ม</p>

  <p>การออดิชั่นของเธอยังเกิดขึ้นในจังหวะที่เหมาะเจาะสำหรับเพลงนี้เอง เพราะ The Cranberries เพิ่งประกาศอัลบั้มการแสดงสดชุดแรกในชื่อ <em>Live at London Astoria II, 1994</em> ซึ่งจะวางจำหน่ายวันที่ 28 สิงหาคม — เป็นเครื่องเตือนใจว่าเพลง “Zombie” ยังคงหาผู้ฟังหน้าใหม่ได้เสมอ แม้จะผ่านมาสามทศวรรษ และผ่านเวที AGT อีกหนึ่งเวที</p>

</div>

<p><strong>Sources:</strong> <a href="https://loudwire.com/nene-royal-stuns-americas-got-talent-audience-cranberries-cover/">Loudwire</a>, <a href="https://www.billboard.com/culture/tv-film/thai-teen-nene-royal-cranberries-zombie-audition-agt-watch-1236289600/">Billboard</a>, <a href="https://meaww.com/who-is-nene-royal-agt-zombie-audition-thai-teen-guitarist-singer-america-got-talent-performance-viral-ozone-band-koo-koo-kangaroo">MEAWW</a>, <a href="https://www.youtube.com/watch?v=TKgAas-84D0">AGT audition clip</a></p>]]></content><author><name>Arthur Reed</name></author><category term="entertainment" /><category term="music" /><summary type="html"><![CDATA[A 16-year-old from Phuket walked onto the AGT stage looking terrified, then ripped into The Cranberries' 'Zombie' and got four yeses.]]></summary></entry><entry><title type="html">Telstra’s Timekeeping Meltdown</title><link href="https://www.dekhub.net/2026/07/09/telstra-timekeeping-outage/" rel="alternate" type="text/html" title="Telstra’s Timekeeping Meltdown" /><published>2026-07-09T00:00:00+00:00</published><updated>2026-07-09T00:00:00+00:00</updated><id>https://www.dekhub.net/2026/07/09/telstra-timekeeping-outage</id><content type="html" xml:base="https://www.dekhub.net/2026/07/09/telstra-timekeeping-outage/"><![CDATA[<div class="lang-en">

  <p>At 4:30am yesterday, somewhere in a data centre on Australia’s east coast, a clock drifted. Not by much — these things never are. But it was enough to knock Telstra’s network sideways for the third major outage in twelve months, and by the time the country woke up, Victoria’s regional trains had stopped, Canberra’s MyWay+ ticketing system was dark, 378 traffic lights in South Australia were frozen mid-cycle, CommBank was telling shopkeepers to switch their EFTPOS terminals over to Optus, and — this is the part that actually matters — people trying to call Triple Zero couldn’t get through.</p>

  <p>Telstra says the fault was in “time synchronisation mechanisms across several nodes,” which is corporate-speak for: the network’s internal clocks stopped agreeing with each other, and everything downstream that assumes they do fell over. If that sentence means something to you in your gut, you’ve probably spent a career staring at genlock or NTP servers wondering why the whole chain just went to black. Turns out national telco infrastructure has the same Achilles’ heel as a studio truck: sync drifts, and suddenly nothing talks to anything.</p>

  <p>The kicker landed overnight. Telstra thought it had this fixed by yesterday evening. Instead, a secondary fault surfaced, again hitting Triple Zero calls — Telstra says it’s cut the error rate by roughly 90% but it’s not zero, and welfare checks are underway for customers whose emergency calls silently failed. Over 100,000 customers are potentially affected by the secondary issue alone.</p>

  <p>This isn’t a one-off. Optus had two national outages last year — the September one is linked to two deaths, from people who couldn’t reach emergency services. Vodafone went down nationally in June. Telstra’s now had two failures in two days on top of that history.</p>

  <blockquote>
    <p>“Telcos are the least trusted industry in our country as we stand today, and days like today demonstrate why Australians feel that way. It will be up to Telstra to make things right.” — Federal Communications Minister Anika Wells</p>
  </blockquote>

  <p>Consumer group ACCAN called it “the latest in a spate of reliability flashpoints across the Australian telco sector.” The Communications Workers Union blamed Telstra’s own staffing cuts. Take your pick of villains — the pattern is the actual story now, not any single outage.</p>

  <p>Here’s the real takeaway, and it’s not “boycott Telstra” — every Australian carrier shares towers, backhaul, and apparently a taste for timekeeping bugs. A second SIM from a different retail brand doesn’t buy you real redundancy if it’s still riding the same physical network underneath. Actual redundancy is a path that doesn’t touch any terrestrial network at all — a satellite communicator, something like a Garmin inReach or a Zoleo, that talks straight to a constellation instead of a cell tower, for the mornings when the entire ground-based system — not just your provider — has a bad day.</p>

  <div class="cta-box">
<span class="tag">Worth trying</span>
<p>A dual-SIM phone doesn't save you when the outage is upstream of every carrier. A dedicated satellite communicator (Garmin inReach Mini 2, Zoleo) talks straight to a satellite constellation instead of a cell tower — the one piece of comms gear that's genuinely independent of a day like this one.</p>
</div>

</div>

<div class="lang-th" lang="th">

  <p>เมื่อเวลา 4:30 น. เมื่อวานนี้ ที่ไหนสักแห่งในดาต้าเซ็นเตอร์บนชายฝั่งตะวันออกของออสเตรเลีย นาฬิกาเรือนหนึ่งเกิดคลาดเคลื่อน ไม่มากนัก — เรื่องแบบนี้ไม่เคยมากอยู่แล้ว แต่ก็มากพอที่จะทำให้เครือข่ายของ Telstra สั่นคลอนจนเกิดเหตุขัดข้องครั้งใหญ่เป็นครั้งที่สามในรอบสิบสองเดือน และเมื่อประเทศตื่นขึ้นมา รถไฟในชนบทของรัฐวิกตอเรียก็หยุดวิ่ง ระบบตั๋ว MyWay+ ของแคนเบอร์ราดับมืด สัญญาณไฟจราจร 378 จุดในเซาท์ออสเตรเลียค้างอยู่กลางรอบ ธนาคาร CommBank บอกร้านค้าให้เปลี่ยนเครื่อง EFTPOS ไปใช้เครือข่าย Optus แทน และ — ส่วนที่สำคัญที่สุดจริง ๆ — คนที่พยายามโทรแจ้งเหตุฉุกเฉิน Triple Zero โทรไม่ติด</p>

  <p>Telstra ระบุว่าความผิดพลาดอยู่ที่ “กลไกการซิงค์เวลาในหลายโหนด” ซึ่งเป็นภาษาทางการที่แปลว่า นาฬิกาภายในเครือข่ายหยุดตรงกัน และทุกอย่างที่อยู่ปลายทางซึ่งอ้างอิงว่ามันตรงกันก็ล้มลงตาม ถ้าประโยคนี้ทำให้คุณรู้สึกสะดุ้งในใจ คุณอาจเคยใช้ชีวิตทั้งอาชีพจ้องมอง genlock หรือเซิร์ฟเวอร์ NTP สงสัยว่าทำไมทั้งระบบถึงดับไปพร้อมกัน กลายเป็นว่าโครงสร้างพื้นฐานโทรคมนาคมระดับชาติก็มีจุดอ่อนแบบเดียวกับรถบรรทุกสตูดิโอ นั่นคือ การซิงค์คลาดเคลื่อน แล้วจู่ ๆ ทุกอย่างก็คุยกันไม่รู้เรื่อง</p>

  <p>จุดพลิกผันเกิดขึ้นข้ามคืน Telstra คิดว่าแก้ปัญหาเสร็จแล้วตั้งแต่เย็นวานนี้ แต่กลับมีความผิดพลาดรองเกิดขึ้นอีก กระทบสายเรียก Triple Zero อีกครั้ง — Telstra ระบุว่าลดอัตราความผิดพลาดลงราว 90% แต่ก็ยังไม่เป็นศูนย์ และกำลังมีการตรวจสอบความปลอดภัยของลูกค้าที่สายฉุกเฉินล้มเหลวแบบเงียบ ๆ ลูกค้ากว่า 100,000 รายอาจได้รับผลกระทบจากปัญหารองนี้เพียงอย่างเดียว</p>

  <p>นี่ไม่ใช่เหตุการณ์ครั้งเดียว Optus เคยเกิดเหตุขัดข้องทั่วประเทศสองครั้งเมื่อปีที่แล้ว — เหตุการณ์เดือนกันยายนเชื่อมโยงกับผู้เสียชีวิตสองราย ที่ติดต่อหน่วยฉุกเฉินไม่ได้ Vodafone ก็ล่มทั่วประเทศเมื่อเดือนมิถุนายน และตอนนี้ Telstra เองก็เกิดความผิดพลาดสองครั้งในสองวันซ้อนทับกับประวัติเดิม</p>

  <blockquote>
    <p>“โทรคมนาคมคืออุตสาหกรรมที่ได้รับความไว้วางใจน้อยที่สุดในประเทศของเราตอนนี้ และวันแบบวันนี้ก็แสดงให้เห็นว่าทำไมชาวออสเตรเลียถึงรู้สึกแบบนั้น ต่อจากนี้ Telstra ต้องรับผิดชอบแก้ไขให้ถูกต้อง” — Anika Wells รัฐมนตรีว่าการกระทรวงการสื่อสารกลาง</p>
  </blockquote>

  <p>กลุ่มผู้บริโภค ACCAN เรียกเหตุการณ์นี้ว่า “อีกหนึ่งในชุดเหตุการณ์ที่บั่นทอนความน่าเชื่อถือทั่วภาคโทรคมนาคมของออสเตรเลีย” สหภาพแรงงานสื่อสารตำหนิว่าเป็นผลจากการลดพนักงานของ Telstra เอง จะโทษใครก็แล้วแต่ รูปแบบที่เกิดซ้ำ ๆ ต่างหากที่เป็นเรื่องจริงตอนนี้ ไม่ใช่เหตุขัดข้องครั้งใดครั้งหนึ่ง</p>

  <p>ประเด็นที่แท้จริงไม่ใช่ “เลิกใช้ Telstra” — เพราะผู้ให้บริการทุกรายในออสเตรเลียใช้เสาสัญญาณและโครงข่ายส่งข้อมูลร่วมกัน และดูเหมือนจะมีจุดอ่อนเรื่องการจับเวลาเหมือนกันหมด ซิมสำรองจากอีกแบรนด์หนึ่งไม่ได้ให้ความซ้ำซ้อนที่แท้จริง ถ้ามันยังวิ่งอยู่บนโครงข่ายกายภาพเดียวกันข้างใต้ ความซ้ำซ้อนที่แท้จริงคือช่องทางที่ไม่แตะโครงข่ายภาคพื้นดินเลย เช่น อุปกรณ์สื่อสารผ่านดาวเทียมอย่าง Garmin inReach หรือ Zoleo ที่คุยตรงกับกลุ่มดาวเทียมแทนเสาสัญญาณมือถือ สำหรับเช้าวันที่ระบบภาคพื้นดินทั้งหมด — ไม่ใช่แค่ผู้ให้บริการของคุณ — มีปัญหา</p>

  <div class="cta-box">
<span class="tag">น่าลองใช้</span>
<p>โทรศัพท์สองซิมช่วยไม่ได้ถ้าเหตุขัดข้องเกิดขึ้นต้นทางก่อนถึงผู้ให้บริการทุกราย อุปกรณ์สื่อสารผ่านดาวเทียมโดยเฉพาะ (Garmin inReach Mini 2, Zoleo) คุยตรงกับกลุ่มดาวเทียมแทนเสาสัญญาณมือถือ — อุปกรณ์สื่อสารชิ้นเดียวที่เป็นอิสระจากวันแบบนี้อย่างแท้จริง</p>
</div>

</div>

<p><span class="lang-en"><strong>Sources:</strong></span><span class="lang-th" lang="th"><strong>แหล่งข้อมูล:</strong></span> <a href="https://www.telstra.com.au/exchange/some-mobile-calls-and-data-services-are-affected-today--here-s-w">Telstra Exchange</a>, <a href="https://www.whistleout.com.au/MobilePhones/News/Telstra-secondary-outage-July-2026">WhistleOut</a>, <a href="https://www.telecompaper.com/news/telstra-says-secondary-fault-disrupted-some-emergency-calls-after-outage--1576525">Telecompaper</a>, <a href="https://www.canberratimes.com.au/story/9307078/everything-we-know-about-telstras-widespread-outage/">Canberra Times</a></p>]]></content><author><name>Arthur Reed</name></author><category term="infrastructure" /><category term="telecom" /><category term="gear" /><summary type="html"><![CDATA[A clock drifted in a data centre and knocked out trains, traffic lights, EFTPOS, and Triple Zero calls — Telstra's third major outage in twelve months, and the second in two days.]]></summary></entry><entry><title type="html">The Security Consultant Got Owned By Security 101</title><link href="https://www.dekhub.net/2026/07/09/the-security-consultant-got-owned-by-security-101/" rel="alternate" type="text/html" title="The Security Consultant Got Owned By Security 101" /><published>2026-07-09T00:00:00+00:00</published><updated>2026-07-09T00:00:00+00:00</updated><id>https://www.dekhub.net/2026/07/09/the-security-consultant-got-owned-by-security-101</id><content type="html" xml:base="https://www.dekhub.net/2026/07/09/the-security-consultant-got-owned-by-security-101/"><![CDATA[<div class="lang-en">

  <p>There’s a special kind of schadenfreude reserved for watching a security consultancy get owned by Security 101. This week it was Accenture’s turn.</p>

  <p>A threat actor going by “888” — a handle with previous, mostly unimpressive form against the company — popped up on the cybercrime forum PwnForums claiming to have lifted “just over 35gb” of Accenture’s source code, plus a grab-bag of the stuff that should never leave a vault: RSA keys, SSH keys, Azure personal access tokens, and Azure Storage access keys. As proof, they posted a screenshot showing exfiltration from a private Azure DevOps repo tied to an accenture.com production URL.</p>

  <p>Accenture’s response was the corporate equivalent of stepping over a puddle without acknowledging it’s raining: “aware of this isolated matter,” source “remediated,” no impact to operations, no confirmation of what was actually taken.</p>

  <blockquote>
    <p>Governments and boardrooms spend fortunes on firms whose whole pitch is “we’ll audit your posture.” Turns out the audit doesn’t always start at home.</p>
  </blockquote>

  <p>Here’s the part that should needle anyone who’s run a CI/CD pipeline: none of the alleged haul is exotic. It’s not a zero-day, not some nation-state supply-chain masterstroke. If the claims hold up, it’s the oldest story in DevOps — long-lived tokens and keys sitting in a repo where a compromised credential or a leaked config file was enough to walk out the door with the crown jewels. Accenture’s entire commercial pitch to clients is “we’ll help you not do this.” The gap between the brochure and the breach report is where the comedy lives.</p>

  <p>For anyone running production systems — including a one-person shop wiring together a Python/ffmpeg pipeline with API keys scattered across a CSV-driven batch job — the actual lesson isn’t “don’t get hacked, lol.” It’s that access tokens, SSH keys and API secrets need to live somewhere that isn’t a config file or a Slack DM, with rotation and audit trails, not vibes.</p>

  <div class="cta-box">
<span class="tag">Worth trying</span>
<p>The fix for this exact failure mode is boring on purpose: shared, encrypted, audited storage for team credentials — API keys, SSH keys, access tokens — instead of everyone pasting secrets into a repo, a spreadsheet, or Notion. NordPass Business (and the wider secrets-vaulting category it sits in) is built for precisely this.</p>
</div>

</div>

<div class="lang-th" lang="th">

  <p>มีความสะใจแบบพิเศษที่สงวนไว้สำหรับการได้เห็นบริษัทที่ปรึกษาด้านความปลอดภัยโดนแฮ็กด้วยเรื่องพื้นฐานสุด ๆ อย่าง Security 101 สัปดาห์นี้ถึงคิวของ Accenture</p>

  <p>แฮกเกอร์ที่ใช้ชื่อ “888” — บัญชีที่เคยมีผลงานไม่ค่อยน่าประทับใจกับบริษัทนี้มาก่อน — โผล่ขึ้นมาบนฟอรัมอาชญากรรมไซเบอร์ PwnForums อ้างว่าได้ขโมยซอร์สโค้ดของ Accenture ไปแล้ว “กว่า 35GB เล็กน้อย” พร้อมกับของอื่น ๆ ที่ไม่ควรหลุดออกจากตู้เซฟเด็ดขาด ทั้ง RSA key, SSH key, Azure personal access token และ Azure Storage access key เพื่อเป็นหลักฐาน พวกเขาโพสต์ภาพหน้าจอที่แสดงการดึงข้อมูลออกจากรีโพซิทอรี Azure DevOps ส่วนตัวที่เชื่อมโยงกับ URL การใช้งานจริงของ accenture.com</p>

  <p>การตอบสนองของ Accenture เทียบได้กับการก้าวข้ามแอ่งน้ำโดยไม่ยอมรับว่าฝนกำลังตก คือ “รับทราบเหตุการณ์ที่เกิดขึ้นแบบแยกส่วนนี้” ต้นตอ “ได้รับการแก้ไขแล้ว” ไม่มีผลกระทบต่อการดำเนินงาน และไม่ยืนยันว่าจริง ๆ แล้วอะไรถูกขโมยไปบ้าง</p>

  <blockquote>
    <p>รัฐบาลและห้องประชุมบอร์ดบริหารทุ่มเงินมหาศาลให้บริษัทที่ขายไอเดีย “เราจะตรวจสอบความปลอดภัยให้คุณ” กลายเป็นว่าการตรวจสอบนั้นไม่ได้เริ่มจากตัวเองเสมอไป</p>
  </blockquote>

  <p>ส่วนที่ควรกวนใจใครก็ตามที่เคยดูแล pipeline CI/CD คือ ไม่มีอะไรในของที่ถูกอ้างว่าขโมยไปเป็นเรื่องพิเศษเลย ไม่ใช่ zero-day ไม่ใช่แผนโจมตี supply-chain ระดับรัฐชาติ ถ้าข้อกล่าวหาเป็นจริง นี่คือเรื่องเก่าแก่ที่สุดในวงการ DevOps นั่นคือ โทเคนและคีย์ที่อยู่ในรีโพนานเกินไป จนแค่ข้อมูลรับรองที่ถูกขโมยหรือไฟล์คอนฟิกที่หลุดออกไปก็เพียงพอจะเดินออกไปพร้อมของมีค่าที่สุดได้ ทั้งที่ธุรกิจหลักของ Accenture คือขายไอเดีย “เราจะช่วยไม่ให้คุณทำแบบนี้” ให้ลูกค้า ช่องว่างระหว่างโบรชัวร์กับรายงานการรั่วไหลนี่แหละคือจุดที่ตลกร้ายอยู่</p>

  <p>สำหรับใครก็ตามที่ดูแลระบบโปรดักชัน — รวมถึงทีมคนเดียวที่ต่อ pipeline Python/ffmpeg เข้าด้วยกันโดยมี API key กระจัดกระจายอยู่ในไฟล์ CSV ที่ขับเคลื่อน batch job — บทเรียนจริง ๆ ไม่ใช่ “อย่าโดนแฮ็กสิ” แต่คือโทเคนการเข้าถึง SSH key และความลับของ API ต้องถูกเก็บไว้ในที่ที่ไม่ใช่ไฟล์คอนฟิกหรือข้อความ DM ใน Slack ต้องมีการหมุนเวียนและบันทึกการตรวจสอบ ไม่ใช่แค่ความรู้สึกว่าปลอดภัย</p>

  <div class="cta-box">
<span class="tag">น่าลองใช้</span>
<p>ทางแก้สำหรับความผิดพลาดรูปแบบนี้นั้นน่าเบื่อโดยตั้งใจ คือที่เก็บข้อมูลรับรองของทีมแบบเข้ารหัสและตรวจสอบได้ ทั้ง API key, SSH key, access token แทนที่ทุกคนจะแปะความลับลงในรีโพ สเปรดชีต หรือ Notion NordPass Business (และหมวดหมู่การจัดเก็บความลับที่กว้างกว่านั้น) ถูกสร้างมาเพื่อสิ่งนี้โดยเฉพาะ</p>
</div>

</div>

<p><span class="lang-en"><strong>Sources:</strong></span><span class="lang-th" lang="th"><strong>แหล่งข้อมูล:</strong></span> <a href="https://www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/">Help Net Security</a>, <a href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/">Bleeping Computer</a>, <a href="https://cybernews.com/security/accenture-data-breach-source-code-leak/">Cybernews</a>, <a href="https://gbhackers.com/accenture-data-breach-exposes-35gb-source-code/">GBHackers</a></p>]]></content><author><name>Arthur Reed</name></author><category term="security" /><category term="saas" /><category term="dev-tools" /><summary type="html"><![CDATA[Accenture — the firm companies pay to tell them how not to get hacked — just confirmed a breach of its own Azure DevOps repo. Alleged haul: 35GB of source code, RSA keys, SSH keys, and access tokens.]]></summary></entry><entry><title type="html">The Bug That Outlived Three Presidents</title><link href="https://www.dekhub.net/2026/07/08/the-bug-that-outlived-three-presidents/" rel="alternate" type="text/html" title="The Bug That Outlived Three Presidents" /><published>2026-07-08T00:00:00+00:00</published><updated>2026-07-08T00:00:00+00:00</updated><id>https://www.dekhub.net/2026/07/08/the-bug-that-outlived-three-presidents</id><content type="html" xml:base="https://www.dekhub.net/2026/07/08/the-bug-that-outlived-three-presidents/"><![CDATA[<div class="lang-en">

  <p>Somewhere in a data center, a piece of software called Squid — the humble proxy server that’s been quietly routing web traffic since the Clinton administration — has been leaking people’s passwords in plain text. For twenty-nine years. Nobody noticed.</p>

  <p>It took an AI to catch it.</p>

  <p>The bug, now cheekily nicknamed “Squidbleed” (CVE-2026-47729, a nod to the infamous Heartbleed), is a classic heap over-read: Squid’s code checks for whitespace in a chunk of text without first checking whether it’s run off the end of the buffer. When it does, it reads whatever happens to be sitting in adjacent memory — which, on a busy shared proxy, might be a stranger’s login credentials from the request before yours. Confidentiality-only, no crash, no dramatic hack. Just twenty-nine years of one user occasionally getting handed a taste of somebody else’s session.</p>

  <p>The part that stings: this is the kind of bug security researchers are trained to look for. Buffer boundary checks are Auditing 101. It sat in open-source code, readable by anyone, for nearly three decades. What finally caught it wasn’t a human at all — it was Anthropic’s Claude Mythos, sniffing around old C code the way it’s apparently started doing to FFmpeg and other creaky infrastructure projects, and flagging the exact <code class="language-plaintext highlighter-rouge">strchr()</code> call that everyone else’s eyes had slid past since 1997.</p>

  <blockquote>
    <p>Governments spent the last few years worrying about frontier AI models being restricted for “national security risk.” Turns out one of those models’ actual day job is finding the vulnerabilities a small army of human pentesters missed for three decades.</p>
  </blockquote>

  <p>The fix, for the record, is unglamorous: a null-terminator check, merged back in April. If you’re running Squid anywhere in your stack, patch it.</p>

  <p>The bigger takeaway for the rest of us: this bug specifically leaked credentials — usernames, passwords, API keys — sitting in cleartext HTTP headers. The one thing standing between “your password briefly existed in someone else’s memory buffer” and “your password is now useless to whoever grabbed it” is whether you were reusing that password anywhere else, or whether it was sitting in a proper vault instead of your browser’s autofill.</p>

  <div class="cta-box">
<span class="tag">Worth trying</span>
<p>If a 29-year-old bug in boring infrastructure software can expose plaintext credentials, the cheapest insurance is simply never reusing a password in the first place. A dedicated password manager (1Password, Bitwarden, or the NordPass/NordVPN family) closes this hole entirely — even a full credential leak becomes a non-event if nothing was reused.</p>
</div>

</div>

<div class="lang-th" lang="th">

  <p>ที่ไหนสักแห่งในดาต้าเซ็นเตอร์ ซอฟต์แวร์ตัวหนึ่งชื่อ Squid — พร็อกซีเซิร์ฟเวอร์ธรรมดาที่คอยส่งต่อทราฟฟิกเว็บมาตั้งแต่ยุคของประธานาธิบดีคลินตัน — กำลังรั่วไหลรหัสผ่านของผู้คนแบบข้อความธรรมดามานานถึง 29 ปี โดยไม่มีใครสังเกตเห็น</p>

  <p>ต้องใช้ AI ถึงจะจับได้</p>

  <p>บั๊กตัวนี้ ซึ่งตอนนี้ถูกตั้งฉายาเล่น ๆ ว่า “Squidbleed” (CVE-2026-47729 ล้อกับ Heartbleed อันโด่งดัง) เป็นบั๊กประเภท heap over-read แบบคลาสสิก โค้ดของ Squid ตรวจสอบช่องว่าง (whitespace) ในข้อมูลชุดหนึ่งโดยไม่ได้เช็คก่อนว่าตำแหน่งอ่านเลยขอบเขตของบัฟเฟอร์ไปแล้วหรือยัง เมื่อมันเลยขอบเขต มันจะอ่านสิ่งที่อยู่ในหน่วยความจำถัดไป ซึ่งบนพร็อกซีที่ใช้งานร่วมกันจำนวนมาก อาจเป็นข้อมูลรับรองการเข้าสู่ระบบของคนแปลกหน้าจากคำขอก่อนหน้าคุณ เป็นเพียงการรั่วไหลของความลับเท่านั้น ไม่มีการแครช ไม่มีการแฮกที่ดูดราม่า มีแค่ 29 ปีที่บางครั้งผู้ใช้คนหนึ่งได้รับ “รสชาติ” ของเซสชันคนอื่นไปโดยไม่รู้ตัว</p>

  <p>ส่วนที่เจ็บแสบคือ นี่คือประเภทของบั๊กที่นักวิจัยด้านความปลอดภัยถูกฝึกมาให้มองหา การตรวจสอบขอบเขตของบัฟเฟอร์คือพื้นฐานของ Auditing 101 มันซ่อนอยู่ในโค้ดโอเพนซอร์สที่ใครก็อ่านได้มาเกือบสามทศวรรษ สิ่งที่จับมันได้ในที่สุดไม่ใช่มนุษย์เลย แต่คือ Claude Mythos ของ Anthropic ที่กำลังไล่ตรวจโค้ด C เก่า ๆ เหมือนที่มันเริ่มทำกับ FFmpeg และโปรเจกต์โครงสร้างพื้นฐานเก่าแก่อื่น ๆ และชี้ไปที่การเรียก <code class="language-plaintext highlighter-rouge">strchr()</code> ตัวที่สายตาของทุกคนมองข้ามมาตั้งแต่ปี 1997</p>

  <blockquote>
    <p>รัฐบาลหลายประเทศใช้เวลาไม่กี่ปีที่ผ่านมากังวลเรื่องการจำกัดโมเดล AI แนวหน้าเพราะ “ความเสี่ยงด้านความมั่นคงของชาติ” กลายเป็นว่างานประจำจริง ๆ ของโมเดลตัวหนึ่งคือการหาช่องโหว่ที่ทีมนักทดสอบเจาะระบบมนุษย์จำนวนมากมองข้ามมานานสามทศวรรษ</p>
  </blockquote>

  <p>ทางแก้ ถ้าจะพูดตรง ๆ ก็ไม่หวือหวาอะไร แค่การตรวจสอบ null-terminator ที่ถูกรวมเข้าโค้ดหลักไปแล้วตั้งแต่เดือนเมษายน ถ้าคุณมี Squid อยู่ในระบบของคุณที่ไหนก็ตาม รีบแพตช์ซะ</p>

  <p>ประเด็นสำคัญกว่าสำหรับพวกเราที่เหลือคือ บั๊กนี้รั่วไหลข้อมูลรับรอง (credentials) โดยเฉพาะ ทั้งชื่อผู้ใช้ รหัสผ่าน API key ที่อยู่ในเฮดเดอร์ HTTP แบบไม่เข้ารหัส สิ่งเดียวที่คั่นระหว่าง “รหัสผ่านของคุณเคยอยู่ในหน่วยความจำของคนอื่นชั่วขณะ” กับ “รหัสผ่านของคุณตอนนี้ไร้ประโยชน์สำหรับใครก็ตามที่ขโมยไปแล้ว” คือคุณใช้รหัสผ่านนั้นซ้ำที่อื่นหรือไม่ หรือมันถูกเก็บไว้ในตู้เซฟที่เหมาะสมแทนที่จะเป็นระบบจดจำรหัสผ่านอัตโนมัติของเบราว์เซอร์</p>

  <div class="cta-box">
<span class="tag">น่าลองใช้</span>
<p>ถ้าบั๊กอายุ 29 ปีในซอฟต์แวร์โครงสร้างพื้นฐานธรรมดา ๆ ยังสามารถเปิดเผยข้อมูลรับรองแบบไม่เข้ารหัสได้ ประกันภัยที่ถูกที่สุดคือการไม่ใช้รหัสผ่านซ้ำที่ไหนเลยตั้งแต่แรก โปรแกรมจัดการรหัสผ่านโดยเฉพาะ (1Password, Bitwarden หรือตระกูล NordPass/NordVPN) จะปิดช่องโหว่นี้ได้ทั้งหมด แม้ข้อมูลรับรองจะรั่วไหลทั้งหมด ก็ไม่มีผลกระทบใด ๆ ถ้าไม่มีการใช้ซ้ำ</p>
</div>

</div>

<p><span class="lang-en"><strong>Sources:</strong></span><span class="lang-th" lang="th"><strong>แหล่งข้อมูล:</strong></span> <a href="https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html">The Hacker News</a>, <a href="https://www.theregister.com/security/2026/06/23/mythos-discovers-squidbleed-a-memory-leak-thats-gone-undetected-since-clinton-era/5260367">The Register</a>, <a href="https://cybersecuritynews.com/squidbleed-vulnerability/">CyberSecurityNews</a></p>]]></content><author><name>Arthur Reed</name></author><category term="security" /><category term="ai" /><category term="dev-tools" /><summary type="html"><![CDATA[A 29-year-old bug in Squid Proxy has been leaking passwords in plain text since the Clinton administration. It took an AI to finally catch it — and the irony is hard to miss.]]></summary></entry></feed>