AI Infrastructure Risk, Identity & Governance, Incidents & Breaches, Security Operations

Research Digest: Thai Personal Data Exposure Study Finds 1.2 Million National ID Records Indexed Online

A research paper reports that more than 1.2 million Thai National Identification Numbers were exposed through pages indexed by search engines. This Nogosee research digest translates the paper abstract into English context, links the full paper, and explains the operational relevance for privacy, identity, government web governance, and East Asia risk monitoring.

Read more

Identity & Governance, Incidents & Breaches, Security Operations, Vulnerability Intelligence

Japanese Automaker Data Breach and South Korean Steel Ransomware Attack Highlight East Asia Cyber Threats

In March 2026, a Japanese automaker suffered a personal data breach via unauthorized external access, while INC Ransom targeted a South Korean steel manufacturer in a ransomware attack. Simultaneously, the administrator of the LeakBase dark web forum was arrested in Russia. These incidents underscore ongoing cyber risks to manufacturing sectors in Japan and South Korea, with implications for supply chain security and threat actor infrastructure disruption.

Read more

AI Security, Cloud Security, Incidents & Breaches, Security Operations

Iranian Cyber Campaign Targets South Korean Electronics Manufacturing for Intellectual Property Theft

A targeted cyber-espionage campaign attributed to the Iran-linked MuddyWater group successfully breached a major South Korean electronics manufacturer in early 2026. The operation utilized DLL sideloading and legitimate service abuse to conduct industrial reconnaissance and credential theft, signaling a shift toward more operationally mature and quiet attacks against high-value East Asian industrial targets.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

How Operators Can Monitor JPCERT/CC Alerts for Japan Infrastructure Risk

Monitor JPCERT/CC alerts as a primary source for Japanese enterprise and infrastructure risk, focusing on vendor advisories, exploitation signals, and exposure relevant to global security teams. This evergreen playbook outlines how to use the official JPCERT/CC RSS feed for continuous monitoring without treating it as breaking news.

Read more

Cloud Security, Incidents & Breaches, Security Operations, Vulnerability Intelligence

Windows Web Server Exploitation Trends: Analysis of Q1 2026 Attack Patterns

AhnLab SEcurity intelligence Center (ASEC) reports persistent targeting of Windows-based IIS and Apache Tomcat servers in Q1 2026. Attackers, notably the Larva-26001 threat actor, utilize web shell command execution, privilege escalation exploits like JuicyPotato, and port-forwarding tools to seize control of infected systems through RDP-mediated access and internal network lateral movement.

Read more

Cloud Security, Identity & Governance, Incidents & Breaches, Security Operations

Larva-26002 Targets Windows Database Servers with ICE Cloud Malware in Q1 2026

The Larva-26002 threat actor is aggressively targeting mismanaged MS-SQL and MySQL servers on Windows. According to ASEC’s Q1 2026 report, the group has evolved its toolkit to include ICE Cloud, a Go-based scanner. Attacks involve brute-force credential stuffing and exploiting the BCP utility to deploy malware for subsequent ransomware or reconnaissance operations.

Read more