Cybersecurity

Login required for search functionality | Get a free-level account with Google/Microsoft single-sign-on.

172 reports

Cyber Risks Brief - July 23, 2026

Regional cyber espionage, new data classification policies, artificial intelligence threats, and severe software vulnerabilities require immediate risk mitigation and security compliance

Taiwan Announces Mobile Network Disruption Drills; A Quick Look at China’s Offensive Cyber Operations

Taiwan will simulate mobile network disruptions during upcoming urban resilience exercises to prepare citizens and test infrastructure against offensive cyber operations. Businesses should establish redundant network connections to maintain operational resilience.

Newly Uncovered Cyber-Espionage Malware Targets Government and Diplomatic Entities in Southeast Asia

An active cyberespionage campaign targeting government and diplomatic entities in Southeast Asia underscores growing regional risk. State-aligned threat actors increasingly target critical infrastructure, fueled by rising geopolitical competition across the Asia Pacific region.

Microsoft’s Monthly Patch - July 2026: 570 Vulnerabilities Fixed, Including 3 Zero-Days; Microsoft Anticipates AI Scanning to Drive up Vulnerability Count

Microsoft released its July security update addressing five hundred seventy vulnerabilities, including three zero-day flaws. With the integration of artificial intelligence into vulnerability scanning, organizations must prepare for an increased volume of security patches.

AI's Escalating Role in Cyberattacks and Vulnerability Scanning

A new cybercrime platform leverages artificial intelligence to target Microsoft accounts and bypass multi-factor authentication. By automating convincing lures and hijacking active user sessions, this service lowers barriers for attackers and heightens enterprise security risks.

Zoom Vulnerability Enables Remote Account Takeover (CVSS 9.8)

Microsoft released its July security update addressing five hundred seventy vulnerabilities, including three zero-day flaws. With the integration of artificial intelligence into vulnerability scanning, organizations must prepare for an increased volume of security patches.

AI-Powered Phishing Targets Microsoft 365 Accounts

A new cybercrime platform leverages artificial intelligence to target Microsoft accounts and bypass multi-factor authentication. By automating convincing lures and hijacking active user sessions, this service lowers barriers for attackers and heightens enterprise security risks.

Strict Digital Infrastructure Regime Proposed in Singapore, While the Philippines Updated its Data Classification

As regional cyber threats escalate, governments in Southeast Asia are tightening digital governance. New regulatory proposals in Singapore and updated data classification policies in the Philippines signal a decisive movement toward securing critical infrastructure.

President Marcos Jr. Signs EO 119 to Modernize Data Management and Classification for Government Agencies

Executive Order Number 119 modernizes digital data management and cybersecurity standards across Philippine government agencies. The directive mandates data classification based on confidentiality and risk levels to enforce strict access and storage protocols.

Phishing Campaign Impersonating Well-known Brands to Steal Google Accounts

A sophisticated job recruitment phishing campaign is impersonating well-known global brands to steal Google accounts. Threat actors utilize nested redirects to bypass security scans and target marketing professionals, exploiting trusted corporate reputations to compromise corporate networks.

Half-Year Cyber Outlook

Analysis of cyber incidents in the Asia-Pacific region reveals that financial gain remains the primary motive for malicious digital activity. Led by criminal networks, these destructive attacks increasingly target public administration and industrial supply chains to exploit sensitive assets.

North Korean APT Group Compromises Open-Source Packages in Supply Chain Attack; A Look into DPRK’s Cyber Strategy

A sophisticated cyber threat group sponsored by North Korea has launched an aggressive supply chain attack, compromising over one hundred open-source packages and browser extensions. The operation shows how state-actors fund state operations and bypass international sanctions.

Pegasus Spyware Tool Found on Former European Parliament Investigating its Misuse: The Importance of Keeping Devices Up to Date

A former European Parliament member investigating the Pegasus spyware tool had his personal device compromised twice. The highly sophisticated zero-click exploit targeted unpatched software vulnerabilities, emphasizing the absolute necessity of maintaining updated systems.

AI Agent Used to Automate Entire Attack Chain: JadePuffer Ransomware

Cybersecurity researchers have identified the first ransomware operation driven entirely by an artificial intelligence agent. The autonomous actor executed the entire attack chain by exploiting vulnerabilities to encrypt databases, marking a new era of automated cyber threat

Cyber Risks Brief - July 9, 2026

Asia-Pacific enterprises face escalating risks from financially motivated cybercrime, state-sponsored espionage targeting critical infrastructure, and advanced software supply chain attacks, alongside emerging threats like automated artificial intelligence ransomware operations.

Microsoft 365 Hit with Aggressive Password-Spraying Campaign Due to Gap in MFA Policy

An aggressive password spraying campaign recently targeted Microsoft 365 environments, exploiting multi factor authentication gaps compromising numerous organizations.

China-Linked Cyber Espionage Group Targets Governments, Critical Infrastructures in Southeast Asia

A Chinese cyberespionage group has expanded its operations into Southeast Asia, targeting government entities and critical energy infrastructure.

Microsoft SharePoint Vulnerability Enables Remote Code Execution: Added to CISA’s KEV List (CVSS 8.8)

Microsoft has disclosed a critical security vulnerability in its SharePoint Server platform that allows authenticated threat actors to execute remote code. The United States Cybersecurity and Infrastructure Security Agency has added this active hazard to its known exploited vulnerabilities list.

Adobe ColdFusion Vulnerability Now being Exploited; Added to CISA’s KEV List (CVSS 10)

Adobe has disclosed a critical vulnerability in its ColdFusion web application development platform that allows threat actors to execute remote code without authentication. The United States government has confirmed active exploitation, urging immediate system updates to prevent compromise.

Critical Information Infrastructure Protection Act and the Cybersecurity Act

These two measures seek to establish a set of standards for the security and protection of critical information infrastructure.

Cyber Risks Brief - June 25, 2026

Cyber crime surges across the Asia Pacific region as the Philippines becomes a focal point for fraudulent operations. Enterprises face severe threats from complex supply chain attacks, massive credential leaks, and critical software vulnerabilities requiring immediate remediation.

FortiBleed Data Leak Exposes Firewall and VPN Credentials

A global data leak known as FortiBleed has exposed the firewall and virtual private network credentials of over seventy-four thousand Fortinet devices. A Russian-speaking threat group utilized recycled credentials and a custom harvesting tool to compromise prominent multinational enterprises

Recent Supply Chain Attacks Compromise LastPass, Mastra AI, Several Organizations

Recent supply chain attacks have compromised multiple organizations, including LastPass and the Mastra Artificial Intelligence framework. By exploiting vendor vulnerabilities and developer accounts, threat actors leverage initial breaches to target downstream networks, amplifying third-party risks.

Recommended Reading: ‘Usbliter8’ Vulnerability Permanently Compromises Secure Boot on Older iPhones

Researchers from Paradigm Shift disclosed a permanent hardware vulnerability in older Apple devices. By bypassing the secure boot chain via a physical connection, the exploit grants control before the OS loads.

Critical Cisco ISE Vulnerability Allows Attacker to Execute Malicious Code Remotely (CVSS 9.1)

Cisco Systems disclosed critical vulnerabilities in its Identity Services Engine that allow remote code execution and data access. By exploiting authorization bypasses and input validation flaws, attackers can escalate privileges to root. Users must apply the official software patches immediately.

Active Splunk Enterprise Flaw Enables Remote Code Execution (CVSS 9.8)

Software provider Splunk disclosed a critical vulnerability allowing unauthenticated remote code execution. Exploiting an authentication flaw in the web interface, attackers can route malicious traffic to an internal database sidecar. Organizations must patch systems immediately.

China’s Crackdown Against Silver Fox Criminal Group Suggests Shift Into Aggressive Cybersecurity Posture

Chinese authorities have dismantled the Silver Fox cybercrime group under an amended Cybersecurity Law. This enforcement highlights a shift toward an aggressive cybersecurity posture with expanded extraterritorial reach, whichy maycomplicating the global regulatory environment for businesses.

Asia-Pacific Region Exhibits a Heightened Cybercrime Environment according to INTERPOL Report

The International Criminal Police Organization reports a sharp rise in cybercrime across the Asia-Pacific region. Driven by artificial intelligence and social engineering, these industrialized threats exploit human lapses, linking financial fraud directly to state espionage.

Fake Business and Financial Documents Used in WhatsApp Malware Distribution Campaign

Threat actors use compromised WhatsApp accounts to distribute malicious files disguised as business documents. These scripts install management tools, granting remote access to devices. Organizations are advised to avoid unmanaged communication platforms.

Hacktivists Deface Senate, House, and NBI Websites

Hacktivists defaced the websites of the Philippine Senate, House of Representatives, and National Bureau of Investigation. Driven by political motives, the successive attacks highlight the persistent threat of hacktivism targeting public institutions amid rising local tensions.

Cyber Risks Brief - June 11, 2026

Global cyber threats are escalating as state-sponsored espionage, ransomware campaigns, and website defacement target critical infrastructure and government entities worldwide. To mitigate these digital risks, organizations are advised to patch critical software flaws immediately.

Philippine Senate Website Defaced by Local Hacktivist Group Nullsec Philippines

The official website of the Philippine Senate was defaced by a local hacktivist group known as Nullsec Philippines. Officials confirmed that no sensitive information was compromised during the incident. The webpage remains under maintenance while government agencies investigate the breach.

Critical VPN Authentication Bypass Exploited By Russia-Based Qilin Ransomware Gang (CVSS 9.3)

Check Point disclosed a critical VPN flaw (CVE-2026-50751) allowing unauthenticated access. Exploited by the Qilin ransomware group for data theft, users are urged to apply patches immediately.

Google Chrome Release Version 149; Stable Release Fixes for 429 Vulnerabilities and Minor Update Fixes 74 Additional Vulnerabilities

Google has issued an emergency update for the Chrome browser to patch hundreds of security flaws. This includes an actively exploited vulnerability within the JavaScript engine that allows remote threat actors to execute malicious code when a user visits a compromised website.

Flaw in Meta AI Support System Result in 20,000 Compromised Instagram Accounts

Threat actors compromised around twenty thousand Instagram accounts by exploiting a security flaw in an artificial intelligence support tool managed by Meta. The system failed to verify identity, allowing attackers to hijack accounts lacking multi-factor authentication.

CISA: ‘Unattributed’ Threat Groups Targeting Internet-Exposed Fuel Monitoring Systems

United States government agencies have issued a critical warning regarding threat actors actively targeting internet-exposed automatic tank gauge systems. These vulnerable devices monitor essential fuel levels across vital infrastructure sectors like energy and transportation.

Microsoft’s Monthly Patch - June 2026: 200 Vulnerabilities, 6 Zero-days

Microsoft has released its June security update fixing two hundred vulnerabilities, including six zero-day flaws. With one critical vulnerability already actively exploited in the wild, organizations must prioritize these patches immediately to protect their networks.

US and Allies Warn of China-Linked Campaign Luring Potential Spies

International intelligence alliance, Five Eyes, has warned that a Chinese espionage campaign is actively using professional networking websites to target government and military personnel. By posing as corporate recruiters, threat actors lure officials into sharing sensitive information.

Pakistan-linked Cyber-Espionage Campaign Uses Highly Targeted Method Directed At Afghanistan

Security researchers discovered a sophisticated cyber espionage campaign directed at the Ministry of Finance in Afghanistan. Suspected Pakistani state actors used targeted emails in local languages to distribute malicious software and access government networks.

Philippines Ranks Above Global Averages For Digital Fraud, Indicating A Rise In Scale Over Severity in Cybercrimes

The Philippine digital fraud rate has surpassed the global average. Driven by low-severity, high-scale tactics like social engineering and text blasters, this fraud-as-a-service landscape requires domestic enterprises to adopt proactive security measures to mitigate risks.

Recent Updates on Supply Chain Attacks

Recent cascading supply chain attacks are targeting software ecosystems. By exploiting developer credentials, automated workflows, and open source repositories, threat actors achieve a massive downstream impact, compromising major artificial intelligence firms.

LiteSpeed Patches Critical cPanel Plugin Vulnerability Allowing Root Privilege Escalation (CVSS 10.0)

LiteSpeed Technologies released security updates addressing a maximum severity vulnerability in its control panel plugin. The actively exploited flaw allows low privilege users to gain root access, risking complete server compromise in shared hosting environments.

Cisco Patches Maximum-Severity Vulnerability in Secure Workload Platform (CVSS 10.0)

Cisco released critical security updates addressing a vulnerability in its Secure Workload platform. The flaw allows unauthenticated remote actors to bypass authentication and gain full administrator control, risking complete network compromise.

Update Now: Ubiquiti Addresses Three Critical UniFi OS Vulnerabilities (CVSS 10.0)

Ubiquiti released critical security updates addressing three vulnerabilities in UniFi Operating System with maximum severity scores. The flaws allow remote actors to make unauthorized changes, access files, or execute commands without user interaction, risking full network control.

Shiny Hunters Targets 7-Eleven, Refuses Ransom Demands

The cybercrime group ShinyHunters leaked stolen cloud documents after 7-Eleven refused extortion demands following a recent data breach. The incident exposed the personal information of thousands of individuals, highlighting global security risks.

Cyber Risks Brief - May 28, 2026

Recent reports highlight critical vulnerabilities across enterprise platforms and severe supply chain attacks. Malicious groups continue to target telecommunications companies and exploit weaknesses, requiring immediate security updates.

China-linked threat actors exploits new Linux and Windows malware to target Telcos

Chinese espionage groups are escalating cyber operations by deploying sophisticated new malware against telecommunications companies. By utilizing custom tools for persistent network access, these actors hide their tracks while gathering high value intelligence across regions.

AI-Generated Investment Scams Impersonating Popular Media Outlets

AI-generated investment scams are increasingly impersonating trusted media outlets like INQUIRER.net, using fake articles and manipulated videos of public figures to lure victims into fraudulent “investment opportunities” aimed at stealing personal information, banking details, and money.

Cyber Risks Brief - May 14, 2026

China-linked espionage targets Philippine infrastructure while AI-generated scams and illegal text blasters exploit local trust. Meanwhile, the Instructure breach exposed data of thousands of institutions, and cascading supply chain attacks continue to compromise major security and software vendors.

Windows DNS Client Remote Code Execution Vulnerability

Microsoft has patched critical buffer overflow vulnerabilities, CVE-2026-41089 and CVE-2026-41096, which enable unauthenticated remote code execution on Windows servers and domain controllers.