Cybersecurity
199 reports
Critical Information Infrastructure Protection Act and the Cybersecurity Act
These two measures seek to establish a set of standards for the security and protection of critical information infrastructure.
Cyber Risks Brief - September 3, 2026
This brief covers cyber espionage operations targeting Philippines and Myanmar government data. Compromised WiFi routers with pre-programed backdoors. Developments in AI generated disinformation campaigns. And, analysis on recent cyberattacks targeting healthcare companies.
A Series of Cyberattacks Targeting Healthcare Companies Conducted by a Single Cybercriminal Group
The United States healthcare sector faces severe cyberattacks from the group ShinyHunters. These breaches threaten data security and signal risks for the Philippines health information services.
Two Pre-Installed Backdoors Found in Chinese-Manufactured Zbtlink Routers
Cybersecurity researchers discovered two pre-installed backdoors in commercial routers manufactured by Zbtlink. These vulnerabilities allow unauthorized remote attackers to execute commands and conduct persistent surveillance.
TerminalFix Social Engineering Technique Uses Fake Verification Prompts to Compromise Systems
The TerminalFix technique tricks individuals into pasting malicious code into their Command Line Interface. This method allows attackers to bypass security limits to execute complex computer scripts.
AI Generated Disinformation Can Now Target Specific Cultures and Languages
State actors employ generative Artificial Intelligence to expand foreign influence. These campaigns leverage automated networks to infiltrate communities and manipulate global policy discourse.
China-linked Cyber Espionage Campaign Targets Myanmar Government with a Malicious Backdoor
China-linked actors target Myanmar officials using phishing and decoy documents in the Burmese language. This campaign focuses on intelligence collection to support regional foreign policy goals.
Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator
A Chinese speaking threat actor targeted the Philippine Nuclear Research Institute and a naval contractor, exploiting known vulnerabilities to steal sensitive nuclear and personnel records.
Cyber Risks Brief - August 20, 2026
This brief covers threat actors exploiting remote access vulnerabilities from hidden back to access cameras of military drones to the disruption of critical infrastructure across continents. We also tackle how North Korea exploits remote work; and urgent security updates for consumer technology.
Joint Advisory Highlights Gunra Ransomware Attacks on Fortinet Devices
The Federal Bureau of Investigation and partners warn that the Gunra ransomware group actively targets critical infrastructure by exploiting known vulnerabilities in Fortinet network appliances.
A Look into Famous Chollima’s Fake IT Worker Hiring Scam
Operatives linked to the Lazarus Group disguise themselves as information technology professionals to infiltrate companies, steal proprietary code, and send funds to North Korea.
Microsoft’s Monthly Patch - August 2026: 400 Vulnerabilities Fixed, Including 3 Zero-Days
Microsoft released its August 2026 update, resolving four hundred vulnerabilities including three zero-day flaws. Administrators must prioritize these security patches to protect critical systems.
Apple Issues Threat Notification Against Users Affected by ‘Mercenary Software’ Spyware Attack
Threat actors are actively exploiting a critical authentication bypass vulnerability found in Microsoft SharePoint. Organizations must apply the latest security updates immediately to secure data assets.
Iran-Linked Cyberattacks Expand to Water Utilities in New Jersey and Alabama
Coordinated cyberattacks targeting water facilities across the United States are expanding. Iranian linked actors are exploiting exposed systems, threatening critical infrastructure security.
Recent AI-Enabled Cyberattack on Taiwan Sheds Light on Evolving Role of AI In State-Sponsored Cyberattacks
Recent reports confirm an artificial intelligence enabled cyberattack targeted Taiwan government agencies. Attackers extracted personnel records, underscoring rising state cybersecurity threats.
East Timor to Combat Online Scam Networks Underscores Regional Momentum Against Organized Cybercrime
The Government of East Timor approved a five year national plan to combat organized cybercrime, online scam networks, and human trafficking, aiming to address significant regional security risks.
CISA Releases Updated Joint Advisory on Medusa Ransomware Group, Over 500 Organizations Hit
The Federal Bureau of Investigation (FBI) and partners issued a warning on Medusa ransomware, which hit five hundred organizations. The group exploits unpatched software to steal and encrypt data.
Threat Actors Exploit Rapid7 Released PoC on Microsoft SharePoint Vulnerability Authentication Bypass (CVSS 9.1)
Threat actors are actively exploiting a critical authentication bypass vulnerability found in Microsoft SharePoint. Organizations must apply the latest security updates immediately to secure data assets.
Analysis on UK Navy Drones Camera Sent Data Back to China
United Kingdom maritime drones recently exposed supply chain risks after components were found sending data to China. This incident highlights vulnerabilities in foreign hardware and the strategic use of commercial technology for state espionage, prompting calls for stricter procurement oversight.
Multiple AI Models Implicated in Breach of Test Environment, Placing Traditional Containment Protocols Under Scrutiny
Recent security incidents disclosed by OpenAI, Anthropic, and Meta revealed that autonomous AI agents escaped test environments due to configuration errors and oversight fatigue. Researchers note that AI capabilities are outpacing standard containment protocols, raising cybersecurity risks.
Thailand’s Finance Ministry Targeted by AI-Driven Cyberattack
Threat intelligence researchers recently identified an artificial intelligence driven intrusion targeting the Thailand Ministry of Finance. The attackers utilized autonomous agents to automate complex cyber operations, signaling a growing trend in offensive digital threats.
China-Linked JadeProx Campaign Targets Government and Healthcare in Asia and Latin America, Further Highlights threat of Impersonation Attacks
The China-linked JadeProx campaign targets government and healthcare sectors globally. Using the new TriBack loader and fake software installers, the threat actors exploit human trust for illicit gain.
South Korea Investigates Possible Data Breach Targeting Diplomatic Academy, Indicating Possible North Korean Cyber Intrusion
The South Korean Ministry of Foreign Affairs reported a data breach at the National Diplomatic Academy. Analysts link the attack to North Korean operatives conducting sophisticated digital espionage.
Microsoft Disclosed Russia-Linked Campaign Targeting Hotel Wifi Networks for Cyber Espionage
Microsoft reports that Russian state actors are compromising hotel wireless internet networks worldwide to conduct cyber espionage. Avoid public networks and prioritize secure connectivity instead.
AI on the Offensive: OpenAI Model Escapes Test Environment, Anthropic and Meta Models Implicated in Misconfiguration Breaches
Artificial intelligence models from OpenAI, Anthropic, and Meta have escaped testing environments to target real systems, exposing critical security gaps that demand better containment strategies.
Fake AI-Generated Vulnerability Reports Flood CVE Pipeline
Artificial Intelligence is flooding the Common Vulnerabilities and Exposures database with fake reports. Cybersecurity firms warn this trend distracts organizations from identifying genuine threats.
CISA Warns of Surge In Cyberattacks Targeting US Water Systems
The Cybersecurity and Infrastructure Security Agency warns of a surge in cyberattacks on water systems. Threat actors are locking operators out of critical equipment exposed to the public internet.
Cyber Risks Brief - August 6, 2026
PSA Intelligence notes rising cyber espionage on APAC government databases and critical infrastructure attacks. Concurrently, AI models are escaping sandboxes to breach systems, and AI-generated phantom threats in CVE databases are wasting security teams' resources.
Cyber Risks Brief - July 23, 2026
Regional cyber espionage, new data classification policies, artificial intelligence threats, and severe software vulnerabilities require immediate risk mitigation and security compliance
Taiwan Announces Mobile Network Disruption Drills; A Quick Look at China’s Offensive Cyber Operations
Taiwan will simulate mobile network disruptions during upcoming urban resilience exercises to prepare citizens and test infrastructure against offensive cyber operations. Businesses should establish redundant network connections to maintain operational resilience.
Newly Uncovered Cyber-Espionage Malware Targets Government and Diplomatic Entities in Southeast Asia
An active cyberespionage campaign targeting government and diplomatic entities in Southeast Asia underscores growing regional risk. State-aligned threat actors increasingly target critical infrastructure, fueled by rising geopolitical competition across the Asia Pacific region.
Microsoft’s Monthly Patch - July 2026: 570 Vulnerabilities Fixed, Including 3 Zero-Days; Microsoft Anticipates AI Scanning to Drive up Vulnerability Count
Microsoft released its July security update addressing five hundred seventy vulnerabilities, including three zero-day flaws. With the integration of artificial intelligence into vulnerability scanning, organizations must prepare for an increased volume of security patches.
AI's Escalating Role in Cyberattacks and Vulnerability Scanning
A new cybercrime platform leverages artificial intelligence to target Microsoft accounts and bypass multi-factor authentication. By automating convincing lures and hijacking active user sessions, this service lowers barriers for attackers and heightens enterprise security risks.
Zoom Vulnerability Enables Remote Account Takeover (CVSS 9.8)
Microsoft released its July security update addressing five hundred seventy vulnerabilities, including three zero-day flaws. With the integration of artificial intelligence into vulnerability scanning, organizations must prepare for an increased volume of security patches.
AI-Powered Phishing Targets Microsoft 365 Accounts
A new cybercrime platform leverages artificial intelligence to target Microsoft accounts and bypass multi-factor authentication. By automating convincing lures and hijacking active user sessions, this service lowers barriers for attackers and heightens enterprise security risks.
Strict Digital Infrastructure Regime Proposed in Singapore, While the Philippines Updated its Data Classification
As regional cyber threats escalate, governments in Southeast Asia are tightening digital governance. New regulatory proposals in Singapore and updated data classification policies in the Philippines signal a decisive movement toward securing critical infrastructure.
President Marcos Jr. Signs EO 119 to Modernize Data Management and Classification for Government Agencies
Executive Order Number 119 modernizes digital data management and cybersecurity standards across Philippine government agencies. The directive mandates data classification based on confidentiality and risk levels to enforce strict access and storage protocols.
Phishing Campaign Impersonating Well-known Brands to Steal Google Accounts
A sophisticated job recruitment phishing campaign is impersonating well-known global brands to steal Google accounts. Threat actors utilize nested redirects to bypass security scans and target marketing professionals, exploiting trusted corporate reputations to compromise corporate networks.
Half-Year Cyber Outlook
Analysis of cyber incidents in the Asia-Pacific region reveals that financial gain remains the primary motive for malicious digital activity. Led by criminal networks, these destructive attacks increasingly target public administration and industrial supply chains to exploit sensitive assets.
North Korean APT Group Compromises Open-Source Packages in Supply Chain Attack; A Look into DPRK’s Cyber Strategy
A sophisticated cyber threat group sponsored by North Korea has launched an aggressive supply chain attack, compromising over one hundred open-source packages and browser extensions. The operation shows how state-actors fund state operations and bypass international sanctions.
Pegasus Spyware Tool Found on Former European Parliament Investigating its Misuse: The Importance of Keeping Devices Up to Date
A former European Parliament member investigating the Pegasus spyware tool had his personal device compromised twice. The highly sophisticated zero-click exploit targeted unpatched software vulnerabilities, emphasizing the absolute necessity of maintaining updated systems.
AI Agent Used to Automate Entire Attack Chain: JadePuffer Ransomware
Cybersecurity researchers have identified the first ransomware operation driven entirely by an artificial intelligence agent. The autonomous actor executed the entire attack chain by exploiting vulnerabilities to encrypt databases, marking a new era of automated cyber threat
Cyber Risks Brief - July 9, 2026
Asia-Pacific enterprises face escalating risks from financially motivated cybercrime, state-sponsored espionage targeting critical infrastructure, and advanced software supply chain attacks, alongside emerging threats like automated artificial intelligence ransomware operations.
Microsoft 365 Hit with Aggressive Password-Spraying Campaign Due to Gap in MFA Policy
An aggressive password spraying campaign recently targeted Microsoft 365 environments, exploiting multi factor authentication gaps compromising numerous organizations.
China-Linked Cyber Espionage Group Targets Governments, Critical Infrastructures in Southeast Asia
A Chinese cyberespionage group has expanded its operations into Southeast Asia, targeting government entities and critical energy infrastructure.
Microsoft SharePoint Vulnerability Enables Remote Code Execution: Added to CISA’s KEV List (CVSS 8.8)
Microsoft has disclosed a critical security vulnerability in its SharePoint Server platform that allows authenticated threat actors to execute remote code. The United States Cybersecurity and Infrastructure Security Agency has added this active hazard to its known exploited vulnerabilities list.
Adobe ColdFusion Vulnerability Now being Exploited; Added to CISA’s KEV List (CVSS 10)
Adobe has disclosed a critical vulnerability in its ColdFusion web application development platform that allows threat actors to execute remote code without authentication. The United States government has confirmed active exploitation, urging immediate system updates to prevent compromise.
Cyber Risks Brief - June 25, 2026
Cyber crime surges across the Asia Pacific region as the Philippines becomes a focal point for fraudulent operations. Enterprises face severe threats from complex supply chain attacks, massive credential leaks, and critical software vulnerabilities requiring immediate remediation.
FortiBleed Data Leak Exposes Firewall and VPN Credentials
A global data leak known as FortiBleed has exposed the firewall and virtual private network credentials of over seventy-four thousand Fortinet devices. A Russian-speaking threat group utilized recycled credentials and a custom harvesting tool to compromise prominent multinational enterprises
Recent Supply Chain Attacks Compromise LastPass, Mastra AI, Several Organizations
Recent supply chain attacks have compromised multiple organizations, including LastPass and the Mastra Artificial Intelligence framework. By exploiting vendor vulnerabilities and developer accounts, threat actors leverage initial breaches to target downstream networks, amplifying third-party risks.