Taiwan Formalizes Tiered ICT Security for Official Travel to Mitigate Espionage Risks

Taiwan's Administration for Cyber Security (ACS) has issued binding guidelines mandating tiered ICT security measures for government personnel traveling abroad, requiring temporary, sanitized devices and data minimization for officials visiting high-risk jurisdictions including mainland China, Hong Kong, and Macau to prevent espionage and data compromise. Read more

Friendly Fire Attack Exposes Fundamental Trust Boundary Flaw in AI Coding Agents

The Friendly Fire proof-of-concept demonstrates how attackers can weaponize AI coding agents through prompt injection in project documentation, achieving remote code execution by exploiting the agent's inability to distinguish between data and executable instructions without modifying the agent itself. Read more

South Korea Ransomware and Dark Web Activity Trends

While the state-sponsored group deployed backdoors (Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE) for espionage, Gunra ransomware was used in parallel attacks for data encryption and exfiltration. Overlapping indicators—including SSH key fingerprints, network infrastructure, and watering hole domains—suggest shared TTPs, though ASEC concludes no definitive collaboration has been proven. The campaign, named 'Operation Double Barrel,' highlights the risk of dual-use exploits in critical financial software supply chains. Read more

Critical Mendix Runtime Vulnerability Exposes User Data via Insecure Inherited Permissions

A critical vulnerability (CVE-2026-7891) in Siemens Mendix Runtime allows privilege escalation and unauthorized access to sensitive user data due to inadequate documentation of System.User entity behavior, enabling misconfigured access rules that expose all records to anonymous users. Read more

Research Digest: Multi-Path Retrieval Enhances L MLLM Improves MLPS Compliance Analysis in China

A new large language model framework integrates hierarchical, tree-based, and tokenization-based retrieval to improve accuracy and traceability in China's Multi-Level Protection Scheme (MLPS) compliance analysis, addressing limitations of general-purpose LLMs in standards-intensive cybersecurity governance. Read more

CISA Advisory Highlights Critical Session Management Flaws in Weintek cMT3092X HMI Used in Global Manufacturing

CISA advisory ICSA-26-204-03 discloses four vulnerabilities in Weintek cMT3092X HMI firmware, including two critical flaws allowing privilege escalation via cookie and token manipulation, plaintext password storage, and improper user management. All affect firmware versions prior to 20210218 and EasyWeb versions prior to v2.1.20. Weintek has released a patch-only update (cmt_typeB_20260316_007.patch) upgrading EasyWeb to 2.3.17-typeb. No public exploitation has been reported to CISA as of the advisory date. The vulnerabilities collectively undermine authentication and authorization in HMI systems deployed in critical manufacturing environments worldwide. Read more

June 2026 Financial Sector Threat Analysis Reveals Multi-Stage Attack Chain Dominance

AhnLab's June 2026 report shows phishing as the top initial attack vector against financial institutions globally, followed by droppers/downloaders and infostealers, with HTML-based smuggling and script-based execution prevalent. Dark web markets actively traded financial data from Canada Life, Robinhood, Prudential, Robinhood, and AYA Bank, while ransomware groups like Lapsus$ and MORPHEUS claimed large-scale data theft. Read more

CylindricalCanine Subgroup Exploits DigiCert Support Portal to Steal Code-Signing Certificates

The stolen certificates were used to sign Zhong Stealer malware, highlighting a critical gap in internal trust controls at certificate authorities. The incident underscores how legitimate support functions, when inadequately isolated, can be weaponized in supply chain attacks targeting software signing infrastructure. Read more

ASEC Weekly Report Maps Ransomware Threats Across Japan Transportation, Food Supply Chains, and Saudi Chemical Sector

ASEC's Week 3, July 2026 threat summary documents three geographically and sectorally distinct cyber incidents: an AiLock ransomware attack on Japan's largest taxi and limousine operator, a cyberattack disrupting operations at Japan's largest frozen food company with cascading supply chain effects, and a DragonForce ransomware incident targeting a Saudi Arabian chemical manufacturer. The report presents these as separate events without technical details or evidence of linkage, serving as a regional situational awareness signal from AhnLab's South Korea-based telemetry. Read more