Cybersecurity
172 reports
Professional Regulation Commission Allegedly Suffers from 9GB Data Leak
The Professional Regulation Commission reportedly suffered a massive data leak involving 9 gigabytes of sensitive licensing documents and personal information. Allegedly executed by the threat actor FEMBOYSEC, the breach underscores critical cybersecurity gaps in the government’s digital shift.
U.S. and Australian Agencies Issue Warnings on Possible Cyberattacks in Connection with Ongoing Conflict in the Middle East
U.S. and Australian agencies have issued joint warnings of potential cyberattacks against financial institutions tied to Middle East tensions. CISA and ACSC urge proactive defense against DDoS and hacktivist threats to mitigate operational, reputational, and regulatory risks.
U.S. and Australian Agencies Issue Warnings on Possible Cyber Attacks Related to Middle East Conflict
US and Australian agencies have warned financial institutions of heightened cyber threats from Iran-aligned actors. Banks face risks of disruptive DDoS attacks and ransomware. Analysts emphasize the need for robust cyber hygiene to prevent operational disruptions and reputational damage.
U.S. and Australian Agencies Issue Warnings on Possible Cyberattacks in Connection with Ongoing Conflict in the Middle East
U.S. and international agencies warn of heightened cyber threats from Iran targeting financial institutions. Organizations face risks of operational disruption via DDoS attacks and reputational damage. Security leaders must prioritize proactive defense and cyber hygiene to mitigate impacts.
Dormant RESURGE Malware Actively Targeting Ivanti Devices
A critical zero-day vulnerability in Ivanti VPN appliances allows remote attackers to gain full system control. State-sponsored actors are using RESURGE malware to maintain hidden, persistent access.
Malicious Chrome Extensions Exploit Gemini AI Browser Panel to Access Cameras and Files
A high-severity vulnerability in Google Chrome allows malicious browser extensions to hijack the Gemini panel. This flaw grants attackers access to cameras, microphones, and local files. Enterprises must ensure all endpoints are updated to Chrome version 143.0.7499.192 or later to mitigate risks.
ClawJacked: Critical Zero-Click Vulnerability in OpenClaw AI Agents
The "ClawJacked" vulnerability in OpenClaw allows remote attackers to hijack local AI agents via malicious websites. This zero-click exploit grants full control over developer environments, including file exfiltration and system commands. Organizations must update to version 2026.2.25.
Exploited Zero-Day Flaw in Windows MSHTML Framework
A zero-day vulnerability in Microsoft HTML allows attackers like APT28 to bypass security warnings and execute code via malicious files. Exploited in the wild, this flaw targets Windows systems. Organizations are advised to apply the February 2026 security updates immediately to mitigate risk.
Dormant RESURGE Malware Actively Targeting Ivanti Devices
A critical zero-day in Ivanti VPNs allows remote attackers to gain full system control via RESURGE malware. State-sponsored actors use this to maintain hidden persistence. Standard patches are insufficient; organizations are advised to use specialized tools to detect the threat.
Angular SSR Vulnerability Enables Unauthorized Server Requests
A critical SSRF vulnerability in the Angular SSR framework allows attackers to redirect internal traffic and exfiltrate sensitive data. With a CVSS of 9.2, this flaw enables private network probing. Organizations are advised to immediately update to Angular version 19.2.21 or higher.
CISA Mandates Patch for Actively Exploited FileZen Vulnerability
A command injection vulnerability in Soliton Systems FileZen allows authenticated users to execute malicious commands. CISA confirmed active exploitation, adding it to the KEV catalog. Organizations are advised to update to version 5.0.11 or later to prevent full system compromise.
SolarWinds Serv-U Software Vulnerable to Administrative-Level Compromise
SolarWinds disclosed four critical vulnerabilities in its Serv-U platform, allowing attackers to execute commands with administrator privileges. With a CVSS of 9.1, these flaws pose a severe risk. Organizations are advised to update to version 15.5.4 immediately.
Public Exploit Released for Privilege Escalation Vulnerability in Windows Error Reporting
A privilege escalation vulnerability in Windows Error Reporting allows low-level users to gain administrative control. With a public exploit available, the risk to Windows 10, 11, and Server environments is high. Organizations are advised to apply the January 2026 security updates immediately.
Threat Actors Weaponize PWAs in Fake Google Security Campaign
A phishing campaign uses the fraudulent domain google-prism[.]com to deploy malicious Progressive Web Apps and Android payloads. This attack steals credentials, locations, and contacts while mimicking native Google apps. Organizations should advise users to only use myaccount.google.com.
1Campaign Cybercrime Service Weaponizes Sponsored Search Ads
The 1Campaign service allows threat actors to bypass Google security by hiding malicious ads. Using fraud scoring, it hides phishing sites from scanners while targeting employees via sponsored links. Organizations should implement ad-blocking and mandate the use of official software channels.
Threat Actors Exploit AI Tools for Cyberattacks
Threat actors are weaponizing generative AI tools like CyberStrikeAI and ChatGPT to automate reconnaissance and craft sophisticated phishing campaigns. Additionally, a critical Google Cloud API flaw has exposed sensitive Gemini endpoints, risking massive financial loss and data theft.
Philippine Agencies Expand Digital Oversight: Impact on Social Media and Finance
The DICT retracted its Telegram ban following a cooperation agreement on illegal content monitoring. Simultaneously, the BSP proposed annual cybersecurity self-assessments for financial firms, while authorities intensified crackdowns on illegal lending apps to combat data privacy abuse.
US FBI Intensifies Crackdown Against Southeast Asian Scam Hubs
The FBI partnered with Southeast Asian law enforcement to dismantle industrialized scam compounds linked to organized crime. These hubs utilize forced labor for global "pig butchering" schemes. The joint effort focuses on seizing assets and disrupting transnational cyber fraud networks.
Global Ransomware Attacks Surge 50 Percent in 2025, but Victim Payments Drop to 28 Percent
Global ransomware attacks surged by 50 percent in 2025, but total payments fell as victim payment rates dropped to a record-low 28 percent. Organizations are increasingly refusing to pay, shifting the threat landscape toward data extortion and targeting vulnerable small-to-medium enterprises.
US FBI Intensifies Crackdown Against Southeast Asian Scam Hubs
The FBI and Southeast Asian police are dismantling industrialized scam compounds linked to Chinese organized crime. These hubs utilize forced labor for "pig butchering" schemes, which cost Americans USD 10 billion in 2024. Risks include cyber fraud and diplomatic volatility.
Victim Reportedly Lost Money in Bank Account via Vishing Scam
A sophisticated vishing scam targeted a bank client using stolen personal data and realistic IVR recordings to bypass OTP security. Analysts warn of a developed criminal ecosystem fueled by data breaches and local scam hubs, advising the public to verify all unsolicited calls.
Mobile App “Chat & Ask AI” Allegedly Suffers from a Data Leak
The "Chat & Ask AI" application, with over 50 million downloads, suffered a massive data breach due to a misconfigured Firebase database. The exposure leaked sensitive user conversations and settings, highlighting the risks of unvetted AI "wrapper" apps and Shadow IT in the enterprise.
Study Identifies Vulnerabilities in Password Managers Under Compromised Servers; No Active Exploitation in the Wild
Researchers identified vulnerabilities in major cloud password managers, including Bitwarden and LastPass, that could allow attackers to bypass zero-knowledge protections. While no active exploitation is confirmed, the flaws highlight risks in encrypted data sharing and server security.
Honeywell CCTV Authentication Bypass Flaw (CVSS 9.8)
A critical authentication bypass vulnerability in Honeywell CCTV cameras allows remote attackers to perform full account takeovers by manipulating password recovery APIs. With a severity score of 9.8, the flaw enables unauthorized surveillance, network pivoting, and physical security breaches.
Microsoft’s Monthly Patch February 2026: 58 Vulnerabilities, 6 Zero-days, and Infinite Restart Loop Issue Reported
The February update from Microsoft addresses fifty eight vulnerabilities including six critical zero day threats. While this release secures the Windows Shell and Microsoft Office Word from active exploits, some users report restart errors. Immediate installation is advised to protect systems.
Apple Patches First Zero-Day of 2026: Targeted Attacks Confirm Active Exploit (CVSS 7.8)
Apple disclosed a critical zero-day memory corruption flaw in its dynamic linker service, affecting iPhones, iPads, and Macs. The vulnerability allows attackers to bypass security gatekeepers and execute malicious code at the core operating system level.
Update Now: Google Patches Zero-Day Flaw Exploited in the Wild (CVSS 8.8)
Google disclosed a high-severity "use after free" vulnerability in the Chrome CSS engine. The flaw allows remote code execution via malicious webpages. With active exploitation confirmed, immediate updates are required for all Chromium-based browsers.
State-Sponsored Hackers Weaponize Gemini AI for Cyber Operations
The Google Threat Intelligence Group reported that state-sponsored hackers from Russia, China, Iran, and North Korea are weaponizing the Gemini AI model. These actors use AI to accelerate reconnaissance, automate phishing, and refine malware, significantly increasing the scale of cyberattacks.
Cybercrime Group 0APT Weaponizing Fake Breaches for Real Extortion
Researchers identified "0APT," a cybercrime group using recycled data to falsely claim breaches for extortion. This "disruption without intrusion" tactic weaponizes public trust to cause reputational harm and drain resources, especially impactful for Philippine firms with limited security budgets.
Threat Actors Utilizing Malware to Compromise Devices in Crypto-theft Attacks; Increasing macOS Infection Reported
North Korean threat actors are targeting the fintech industry using AI deepfakes and "ClickFix" tactics to deploy malware on Windows and macOS. By impersonating executives in video calls, they trick victims into executing malicious commands to steal cryptocurrency and sensitive identity data.
Chinese-Linked APT Group Targets Major Singapore Telcos
The China-linked threat actor UNC3886 targeted Singapore’s major telecommunications providers in a sophisticated espionage campaign. By exploiting zero-day vulnerabilities in edge devices, the group harvested network configurations, posing systemic supply-chain risks for the region.
SEC Flags Unregistered Online Lending Apps
Philippines Strengthens Defense Against Financial and AI-Driven Scams
The PNP-ACG and BPI formalized a partnership to combat sophisticated financial crimes through real-time fraud monitoring and intelligence sharing. Concurrently, the CICC warned of deepfake AI being used in romance scams to impersonate individuals and bypass traditional fraud detection methods.
SCAM ALERT: Fake Traffic Violation Text Messages
Authorities are warning against text scams claiming unpaid traffic violations. Fraudsters impersonate agencies like the MMDA to trick victims into clicking malicious links or providing banking data.
Glassworm Malware Hits macOS Developer Tools
Threat actors hijacked a trusted publisher account on the Open VSX Registry to weaponize four popular developer extensions with the Glassworm infostealer. Impacting 22,000 downloads, the malware targets AWS credentials and GitHub tokens to gain insider access to corporate environments.
Coordinated Cyberattacks Hit Poland’s Energy Grid
Volatile Risks of OpenClaw
OpenClaw, a viral AI assistant, has been flagged for a critical remote code execution vulnerability. Due to its high-level system permissions and lack of sandboxing, attackers can use indirect prompt injection to exfiltrate API keys and sensitive corporate data.
AWS Recent Breach Demonstrates AI’ Speed in Compromising Security
An attacker used AI to escalate from a single stolen credential to full AWS administrative control in just eight minutes. This "LLMjacking" incident highlights a shift to machine-speed threats, where attackers automate reconnaissance to hijack cloud resources and bypass traditional defenses.
Two RCE Vulnerabilities in Automation Platform n8n Disclosed (CVSS 9.9 and 8.5)
The workflow automation platform n8n disclosed two critical RCE vulnerabilities. These flaws allow authenticated users to escape sandboxes and execute commands on the host server, risking credential theft and infrastructure-level control across connected services.
Sandbox Escape Vulnerability Found in vm2 NodeJS Library (CVSS 9.8)
A critical sandbox escape vulnerability was disclosed in the vm2 NodeJS library, carrying a CVSS of 9.8. The flaw allows attackers to bypass restricted environments to execute commands, install malware, and steal credentials, impacting software supply chain security.
Russian APT28 Exploiting Recently Patched Microsoft Office Flaw
Russian state-sponsored group APT28 is exploiting a Microsoft Office vulnerability to target government and defense sectors. This "Operation Neusploit" uses compromised documents to bypass security checks, deploying malware for long-term intelligence gathering and data theft.
Notepad++ Update Infrastructure Compromised by State-Sponsored Groups
Chinese state-sponsored threat actors hijacked the Notepad++ update infrastructure to distribute "Chrysalis" malware. This supply chain attack targeted developers and system administrators, weaponizing trusted software updates to maintain persistent remote access for regional espionage.
China-linked “PeckBirdy” Campaign Threatens Southeast Asian Networks
China-linked threat actors are utilizing the PeckBirdy framework to conduct fileless espionage across Southeast Asia. By mimicking legitimate traffic, the campaign targets government and energy infrastructure, including Philippine institutions, to maintain undetected access.
Fake Amazon Recruiters Exploit Job Seekers
Scammers are exploiting Amazon’s reputation to target job seekers with fraudulent offers. By mimicking official branding and moving conversations to encrypted messaging apps, threat actors trick victims into providing sensitive data or paying fake "training" fees under the guise of recruitment.
New Phishing Campaign Exploits Zoom Infrastructure
Researchers uncovered a new Telephone-Oriented Attack Delivery (TOAD) campaign that exploits Zoom’s infrastructure to bypass security filters. By abusing trusted domains to send legitimate-looking emails, attackers lure victims into fraudulent calls to bypass MFA and steal sensitive financial data.
Multiple Ransomware Groups Target Banking, Hospitality, and Tech Sectors
Multiple ransomware groups, including Qilin and Tengu, have claimed attacks on several Philippine firms, such as PSBank and Lenotech. While LM Metro Hotel confirmed a 30GB data breach, other claims remain unverified by authorities, highlighting a surge in local targeting.
SCAM ALERT: Fake Traffic Violation Text Messages
Authorities are warning of a text scam impersonating government agencies like the MMDA and LTO, claiming recipients have unpaid traffic violations. These messages use pressure tactics and malicious links to redirect victims to fake payment portals to steal banking credentials and personal data.
HoneyMyte’s Persistent Threat to Government Networks across Southeast Asia
HoneyMyte has intensified espionage in South East Asia, targeting government networks via DLL side-loading. The group bypasses security to harvest credentials and monitor activity. With 1,400 past victims in the Philippines, their persistence poses a major risk to national critical infrastructure.
Malicious Browser Extensions Steal Credentials and Breach Enterprise Systems
Malicious browser extensions are targeting enterprise HR and ERP platforms to steal credentials and hijack sessions. Campaigns like GhostPoster and ClickFix bypass traditional defenses by exploiting user trust, posing significant risks to corporate data security and operational stability.
Dangers of Free Online Converter Apps
Threat actors are using fake online file converters and malicious advertisements to distribute malware via deceptive CAPTCHAs. Users are warned against using free unverified productivity tools, as these services often lead to system compromise and the exposure of sensitive company data.