Japan supplier cyber risk review for cloud and SaaS teams

Cloud and SaaS teams should use the JVN vulnerability feed to review Japanese supplier exposure through vendor inventory, patch responsibility, internet exposure, compensating controls, and escalation triggers. This checklist provides actionable steps for ongoing risk monitoring without implying new publication or fixed cadences. Read more

Monitoring TWCERT/CC TVN (English) vulnerability notes for Taiwan vendor exposure

This evergreen playbook guides global security, cloud, and operations teams in using the TWCERT/CC English TVN RSS feed to monitor Taiwan-specific vulnerability disclosures and assess vendor exposure. It provides practical, source-grounded steps for integrating this feed into vulnerability management workflows without implying real-time alerts or prescribing rigid schedules. Read more

SLSA questions to ask when a supplier claims ‘secure build pipeline’

Use the SLSA framework to evaluate supplier build integrity through neutral questions on provenance, signing, reproducibility, dependency pinning, and evidence artifacts—without accepting marketing claims as proof. This checklist supports East Asia-facing security, cloud, and supply-chain teams in verifying supplier assertions. Read more

Building an Internal Patch-SLA Queue from Korea KISA/KrCERT Vulnerability Notices: A Practical Workflow Guide

Organizations can transform Korea KISA/KrCERT vulnerability notices into an auditable internal patch-SLA workflow by establishing clear triage steps, ownership rules, severity interpretation, exception tracking, and integration with existing vulnerability management systems—without imposing rigid thresholds or inventing unsupported procedures. Read more

Use the CISA KEV catalog to build an East Asia supplier patch watchlist

This practical tutorial guides security teams in using the CISA Known Exploited Vulnerabilities (KEV) catalog to create a focused, actionable patch watchlist for East Asia-based suppliers. It outlines steps to map KEVs to supplier software inventories, assign ownership, set flexible escalation thresholds, and maintain evidence records—without relying on numeric thresholds or rigid schedules. Read more

ASEC Weekly Report Flags Ransomware on Nova and Dark Web Code Leak Claims in South Korea

ASEC’s Ransom & Dark Web Issues report for week 3 of May 2026 details a ransomware attack on South Korean cosmetics firm Nova, alleged data leakage from an open-source visualization platform attributed to CoinbaseCartel, and claimed source-code theft and sale from a developer platform by TeamPCP, based on AhnLab TIP monitoring. Read more

YellowKey Exploit Exposes TPM-Only BitLocker Gaps in Modern Windows Systems

Microsoft issued a mitigation for CVE-2026-45585 (YellowKey), a zero-day BitLocker bypass allowing physical-access attackers to trigger an unrestricted shell in WinRE via USB-delivered FsTx files and CTRL key input. The flaw affects Windows 11 versions 24H2, 25H2, 26H1 and Windows Server 2025, revealing a critical limitation in TPM-only encryption that requires multi-factor pre-boot authentication to fully mitigate. Read more