GovCERT.HK Issues High Threat Alert on Linux Kernel Privilege Escalation Flaws Zapscape and SCTPhantom

GovCERT.HK has issued a High Threat Security Alert (A26-08-15) for two elevation-of-privilege vulnerabilities in the Linux kernel—Zapscape (CVE-2026-64561) and SCTPhantom (CVE-2026-64564)—with public PoC exploit code available for Zapscape, posing immediate risk of VM escape and host compromise. Read more

A Practical Workflow for A Japanese vendor releases a critical CVE; what should a global security team check first? — 11 August 2026 Review

A Practical Workflow for A Japanese vendor releases a critical CVE; what should a global security team check first? — 11 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for Taiwan semiconductor and manufacturing supplier cyber risk review — 11 August 2026 Review

A Practical Workflow for Taiwan semiconductor and manufacturing supplier cyber risk review — 11 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

Taiwan Formalizes Tiered ICT Security for Official Travel to Mitigate Espionage Risks

Taiwan's Administration for Cyber Security (ACS) has issued binding guidelines mandating tiered ICT security measures for government personnel traveling abroad, requiring temporary, sanitized devices and data minimization for officials visiting high-risk jurisdictions including mainland China, Hong Kong, and Macau to prevent espionage and data compromise. Read more

A Practical Workflow for Turn East Asia CERT feeds into SOC tickets without creating alert noise — 11 August 2026 Review

A Practical Workflow for Turn East Asia CERT feeds into SOC tickets without creating alert noise — 11 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for Japan supplier cyber risk review for cloud and SaaS teams — 11 August 2026 Review

A Practical Workflow for Japan supplier cyber risk review for cloud and SaaS teams — 11 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for How to triage a JPCERT/CC alert in 10 minutes — 11 August 2026 Review

A Practical Workflow for How to triage a JPCERT/CC alert in 10 minutes — 11 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for What to check before escalating an East Asia vulnerability signal — 10 August 2026 Review

A Practical Workflow for What to check before escalating an East Asia vulnerability signal — 10 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

Fairis: A Provable Defense Against Fairness Poisoning in Collaborative Machine Learning

Fairis introduces a server-side reweighting scheme that provably reduces adversarial influence in collaborative ML by weighting client updates based on local fairness scores, offering monotone weight reduction against bias while maintaining positive weights for honest participants, with empirical validation on Taiwan Credit data showing 41–54% weight reduction for stealthy adversaries. Read more

A Practical Workflow for Build a lightweight East Asia vendor risk watchlist from public sources — 10 August 2026 Review

A Practical Workflow for Build a lightweight East Asia vendor risk watchlist from public sources — 10 August 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more