Cloud Security, Incidents & Breaches, Security Operations, Vulnerability Intelligence

Larva-24009 Threat Actor’s 2026 Phishing Campaign Reveals Persistent Use of LNK Malware and Telegram-Based Exfiltration

ASEC’s analysis of a 2026 phishing email campaign by the Larva-24009 threat actor details how LNK files disguised as legitimate documents deploy PowerShell backdoors, QuasarRAT, UltraVNC, and NirSoft tools for credential theft, with persistence via scheduled tasks and exfiltration through the Telegram API, targeting users in Korea and globally.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for Triage a JPCERT/CC Weekly Report entry without overclaiming — 3 August 2026 Review

A Practical Workflow for Triage a JPCERT/CC Weekly Report entry without overclaiming — 3 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for Combine EPSS and KEV to prioritize CVEs without panic — 3 August 2026 Review

A Practical Workflow for Combine EPSS and KEV to prioritize CVEs without panic — 3 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for Convert AWS security bulletins into cloud platform action items — 3 August 2026 Review

A Practical Workflow for Convert AWS security bulletins into cloud platform action items — 3 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for What to extract from a public cyber incident disclosure — 3 August 2026 Review

A Practical Workflow for What to extract from a public cyber incident disclosure — 3 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for How to write an internal alert from a CERT bulletin without exaggeration — 2 August 2026 Review

A Practical Workflow for How to write an internal alert from a CERT bulletin without exaggeration — 2 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for What is JPCERT/CC, and how should global security teams use its alerts? — 2 August 2026 Review

A Practical Workflow for What is JPCERT/CC, and how should global security teams use its alerts? — 2 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for Japan supplier cyber risk review for cloud and SaaS teams — 2 August 2026 Review

A Practical Workflow for Japan supplier cyber risk review for cloud and SaaS teams — 2 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

AI Security, Cloud Security, Incidents & Breaches, Vulnerability Intelligence

A Practical Workflow for Reading JVN vulnerability notes for Japanese product and supplier exposure — 2 August 2026 Review

A Practical Workflow for Reading JVN vulnerability notes for Japanese product and supplier exposure — 2 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims.

Read more

Identity & Governance, Incidents & Breaches, Security Operations, Vulnerability Intelligence

South Korea Ransomware and Dark Web Activity Trends

While the state-sponsored group deployed backdoors (Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE) for espionage, Gunra ransomware was used in parallel attacks for data encryption and exfiltration. Overlapping indicators—including SSH key fingerprints, network infrastructure, and watering hole domains—suggest shared TTPs, though ASEC concludes no definitive collaboration has been proven. The campaign, named ‘Operation Double Barrel,’ highlights the risk of dual-use exploits in critical financial software supply chains.

Read more