A Practical Workflow for Using TWCERT/CC vulnerability notes (English) to monitor Taiwan supply-chain risk

A Practical Workflow for Using TWCERT/CC vulnerability notes (English) to monitor Taiwan supply-chain risk helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

TitanCA: LLM Orchestration for Zero-Day Discovery in Open Source Software

TitanCA, a joint project by Singapore Management University and GovTech Singapore, uses a four-module LLM agent pipeline to discover zero-day vulnerabilities, yielding 118 CVEs from 203 confirmed findings in open-source software, demonstrating a practical approach to reducing SAST false positives through AI orchestration. Read more

A Practical Workflow for What is KrCERT, and when should cloud teams act on South Korea alerts?

A Practical Workflow for What is KrCERT, and when should cloud teams act on South Korea alerts? helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for Build an East Asia AI security watchlist for governance teams

A Practical Workflow for Build an East Asia AI security watchlist for governance teams helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

How Security Teams Can Monitor TWCERT/CC Vulnerability Notes for Taiwan Supplier Risk

This evergreen playbook provides practical workflow guidance for global security, cloud, and operations teams to monitor the TWCERT/CC English TVN RSS feed for Taiwan vendor vulnerability notes. It outlines how to preserve source integrity, separate observable facts from interpretation, and apply Nogosee workflow principles without inventing unsupported claims. The article supports continuous monitoring of thin signals in Taiwan’s cybersecurity landscape while maintaining rigorous evidentiary standards. Read more

AI-Powered Hacking Tools Proliferate Across Platforms, Enabling Autonomous Attack Orchestration in East Asia

Since WormGPT emerged in June 2023, AI-driven hacking tools have spread via dark web, Telegram, GitHub, and Hugging Face, evolving into a hybrid market of paid SaaS and free open-source distribution. These tools automate phishing, malware development, reconnaissance, brute-forcing, vulnerability exploitation, and social engineering, lowering entry barriers while enabling autonomous attack orchestration, as seen in the Bissa Scanner case exploiting CVE-2025-55182 to compromise over 900 systems and steal 65,000+ credential files, including those linked to Anthropic, OpenAI, Google, AWS, Stripe, and PayPal. Read more