AtlasRAT Loader Chain Reveals Builder-Based Malware Framework Targeting WeChat in East Asia

AhnLab ASEC details a four-stage in-memory loader chain for AtlasRAT, a Windows RAT using Delphi-based Flash Player lures, TLS-ChaCha20 C2, offline keylogging, and WeChat.exe DLL injection, with evidence pointing to a builder-based framework rather than a single operator, highlighting implications for regional threat monitoring. Read more

CISA Advisory Highlights Critical Session Management Flaws in Weintek cMT3092X HMI Used in Global Manufacturing

CISA advisory ICSA-26-204-03 discloses four vulnerabilities in Weintek cMT3092X HMI firmware, including two critical flaws allowing privilege escalation via cookie and token manipulation, plaintext password storage, and improper user management. All affect firmware versions prior to 20210218 and EasyWeb versions prior to v2.1.20. Weintek has released a patch-only update (cmt_typeB_20260316_007.patch) upgrading EasyWeb to 2.3.17-typeb. No public exploitation has been reported to CISA as of the advisory date. The vulnerabilities collectively undermine authentication and authorization in HMI systems deployed in critical manufacturing environments worldwide. Read more

CylindricalCanine Subgroup Exploits DigiCert Support Portal to Steal Code-Signing Certificates

The stolen certificates were used to sign Zhong Stealer malware, highlighting a critical gap in internal trust controls at certificate authorities. The incident underscores how legitimate support functions, when inadequately isolated, can be weaponized in supply chain attacks targeting software signing infrastructure. Read more

Research Digest: Music Affect Mapping Shows Geographic Signal but No Population Inference Link

A study of 2,393 folk melodies from 16 countries finds measurable cross-country differences in musical structure, with China showing a distinct wide-leap, high-activity signature, but finds no significant correlation between musical affect and national happiness or individualism indices, rejecting ecological inference. Read more

Converging Ransomware and Data Leak Threats Target South Korea’s Critical Sectors in June 2026

In Week 3 of June 2026, South Korea faced a multi-vector cyber threat landscape as Qilin ransomware struck a big data solution provider, Anubis ransomware targeted a semiconductor equipment parts manufacturer, and confidential defense industry documents appeared for sale on the dark web forum Spear Forums, highlighting coordinated risks to national technological and security assets. Read more

Maintain an ‘evidence ladder’ for East Asia cyber signals

This article provides a practical workflow for maintaining an evidence ladder to assess the strength and reliability of East Asia cyber signals over time. It outlines how to track signal evolution, determine when to upgrade from monitoring to action, and correct prior assumptions transparently without rewriting history. The guidance is designed for security, cloud, and operations teams using Nogosee’s tracker as a monitoring layer. Read more

Trojan and Phishing Dominate Korean Phishing Email Attachments in April 2026

In April 2026, Trojan malware accounted for 47% of phishing email attachments in South Korea, followed by phishing payloads at 39%, according to ASEC analysis. Attackers used social engineering lures like fake tax invoices and logistics notifications, with Trojans often delivered via double-extension files and phishing via HTML spoofs. The share of phishing malware rose from 21% to 39% month-over-month. Read more

Research Digest: Thai Personal Data Exposure Study Finds 1.2 Million National ID Records Indexed Online

A research paper reports that more than 1.2 million Thai National Identification Numbers were exposed through pages indexed by search engines. This Nogosee research digest translates the paper abstract into English context, links the full paper, and explains the operational relevance for privacy, identity, government web governance, and East Asia risk monitoring. Read more

Genians NAC SQL Injection Vulnerability Exposes Network Infrastructure to Data Disclosure

Genians has addressed CVE-2024-23843, a SQL injection vulnerability in its Genian NAC management console. The flaw stems from insufficient validation of user-supplied search parameters, potentially allowing unauthorized data exposure. Organizations using Genian NAC V5.0 or its LTS variants should upgrade to the latest versions to mitigate the risk of database compromise within their security infrastructure. Read more