AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

ASEC Highlights The Gentlemen Ransomware Attack on South Korean IT Distributor Amid Broader Dark Web Threats

ASEC Blog’s Week 5, July 2026 report details a ransomware attack by The Gentlemen group on a South Korean IT software distributor and infrastructure service provider, alongside a Termite ransomware incident targeting a U.S. nonprofit healthcare provider and a ShinyHunters data leak claim involving a global accounting and consulting firm, underscoring persistent ransomware risks to technology service providers and their potential role in supply chain exposure.

Read more

Cloud Security, Incidents & Breaches, Security Operations, Vulnerability Intelligence

CISA Adds Two Actively Exploited Vulnerabilities to KEV Catalog

CISA has added CVE-2025-68686 (Fortinet FortiOS information exposure) and CVE-2026-16812 (Arista VeloCloud Orchestrator command injection) to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation, reinforcing BOD 26-04 requirements for federal agencies and urging all organizations to prioritize patching.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for How to triage a JPCERT/CC alert in 10 minutes — 29 July 2026 Review

A Practical Workflow for How to triage a JPCERT/CC alert in 10 minutes — 29 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

Arista VeloCloud Orchestrator Command Injection Flaw Under Active Exploitation

Attackers are actively exploiting CVE-2026-16812, a critical command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) versions, enabling arbitrary code execution and potential compromise of managed SD-WAN infrastructure. CISA has added the flaw to its KEV catalog with a July 30, 2026 patch deadline for federal agencies.

Read more

AI Security, Cloud Security, Security Operations, Vulnerability Intelligence

OpenAI Open-Sources Codex Security Toolchain for AI-Powered Code Scanning in CI/CD

OpenAI has released the command-line interface and TypeScript SDK for Codex Security as open-source software, enabling developers to scan local code and Git changes for vulnerabilities and integrate checks into pre-commit and CI workflows, though actual analysis relies on OpenAI cloud services and requires authentication via ChatGPT login or API key.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for Create a weekly East Asia cyber risk brief for executives — 27 July 2026 Review

A Practical Workflow for Create a weekly East Asia cyber risk brief for executives — 27 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for A Taiwan supplier appears in a security advisory; how should operations teams assess exposure? — 27 July 2026 Review

A Practical Workflow for A Taiwan supplier appears in a security advisory; how should operations teams assess exposure? — 27 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for Hong Kong finance and cloud security signals worth escalating — 27 July 2026 Review

A Practical Workflow for Hong Kong finance and cloud security signals worth escalating — 27 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for Turn East Asia ransomware reports into a watchlist without panic — 27 July 2026 Review

A Practical Workflow for Turn East Asia ransomware reports into a watchlist without panic — 27 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more