Operation QUICSILVER Exploits Graduation Lures and QUIC Backdoor in Myanmar Cyber Espionage Campaign

Cybersecurity researchers have identified Operation QUICSILVER, a China-nexus espionage campaign targeting Myanmar’s government and IT sectors since April 2026. The attack uses fake graduation ceremony invitations to deliver QUICAgent, a Go-based backdoor that abuses legitimate Windows binaries and communicates via QUIC over UDP port 443 to evade detection. Read more

Research Digest: Assessing Attack Surfaces in Generative Search Engines through Publisher Attributes in Political Domains

A new study evaluates how generative search engines (GSEs) are vulnerable to poisoning attacks by analyzing publisher authority and personalization effects, finding that ruling parties face broader attack surfaces than opposition parties in U.S. and Japan political domains, and that user profiles have minimal influence on citation behavior. Read more

Critical OS Command Injection in Siemens Siveillance Video Management Servers Enables Remote Code Execution

A critical OS command injection vulnerability (CVE-2026-3014, CVSS 9.1) in Siemens Siveillance Video Management Servers allows authenticated users with edit permissions to execute arbitrary code. Siemens has released patched versions for V2023 R3, V2024 R1, and V2025 product lines. CISA urges network isolation and VPN use for remote access. Read more

Siemens Desigo DXR and PXC Controllers Vulnerable to BACnet Packet DoS

A medium-severity denial-of-service vulnerability (CVE-2026-59693) in Siemens Desigo DXR and PXC controllers allows attackers to disrupt building automation systems via malformed BACnet packets, requiring device reset for recovery. Siemens has released patched versions and recommends network segmentation and VPN use for mitigation. Read more

GovCERT.HK Alert Highlights OpenSSL Denial-of-Service Flaw CVE-2026-14456 Across Major Release Lines

GovCERT.HK has issued Security Alert A26-08-24 warning of a denial-of-service vulnerability in OpenSSL versions 3.5.x, 3.6.x, and 4.0.x, patched in releases 3.5.8, 3.6.4, and 4.0.2. Tracked as CVE-2026-14456, the flaw poses availability risks to global infrastructure relying on OpenSSL for TLS, with particular relevance to East Asia’s high-density financial, telecom, and cloud environments. The alert, published August 14, 2026, follows the upstream OpenSSL advisory by one day, underscoring the role of regional CERTs in accelerating patch awareness. Read more

Cisco ASA and FTD Flaw Exploited in the Wild Triggers Remote DoS

Cisco has confirmed active exploitation of CVE-2026-20349 (CVSS 8.6), a high-severity vulnerability in ASA and FTD software allowing unauthenticated remote attackers to trigger device reload via crafted HTTP requests to SSL VPN services, resulting in denial-of-service. The flaw affects multiple versions of ASA and FTD with specific VPN configurations enabled, and has been added to CISA’s KEV catalog with a patch deadline of August 14, 2026 for U.S. federal agencies. No workarounds exist; mitigation requires applying vendor-provided hotfixes. Read more

ASEC Weekly Report Highlights DragonForce, Qilin, and ShinyHunters Activity Across Education, Manufacturing, and Healthcare Sectors in August 2026

ASEC’s August 12, 2026 threat report details ransomware attacks by DragonForce on a Korean online education provider and Qilin on a Korean motor/robotics manufacturer, alongside ShinyHunters’ data theft claim against a U.S. digital healthcare firm, reflecting ongoing regional ransomware trends targeting critical sectors in East Asia and North America. Read more