Taiwan Formalizes Tiered ICT Security for Official Travel to Mitigate Espionage Risks

Taiwan's Administration for Cyber Security (ACS) has issued binding guidelines mandating tiered ICT security measures for government personnel traveling abroad, requiring temporary, sanitized devices and data minimization for officials visiting high-risk jurisdictions including mainland China, Hong Kong, and Macau to prevent espionage and data compromise. Read more

Fairis: A Provable Defense Against Fairness Poisoning in Collaborative Machine Learning

Fairis introduces a server-side reweighting scheme that provably reduces adversarial influence in collaborative ML by weighting client updates based on local fairness scores, offering monotone weight reduction against bias while maintaining positive weights for honest participants, with empirical validation on Taiwan Credit data showing 41–54% weight reduction for stealthy adversaries. Read more

Friendly Fire Attack Exposes Fundamental Trust Boundary Flaw in AI Coding Agents

The Friendly Fire proof-of-concept demonstrates how attackers can weaponize AI coding agents through prompt injection in project documentation, achieving remote code execution by exploiting the agent's inability to distinguish between data and executable instructions without modifying the agent itself. Read more

Larva-24009 Threat Actor’s 2026 Phishing Campaign Reveals Persistent Use of LNK Malware and Telegram-Based Exfiltration

ASEC’s analysis of a 2026 phishing email campaign by the Larva-24009 threat actor details how LNK files disguised as legitimate documents deploy PowerShell backdoors, QuasarRAT, UltraVNC, and NirSoft tools for credential theft, with persistence via scheduled tasks and exfiltration through the Telegram API, targeting users in Korea and globally. Read more

South Korea Ransomware and Dark Web Activity Trends

While the state-sponsored group deployed backdoors (Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE) for espionage, Gunra ransomware was used in parallel attacks for data encryption and exfiltration. Overlapping indicators—including SSH key fingerprints, network infrastructure, and watering hole domains—suggest shared TTPs, though ASEC concludes no definitive collaboration has been proven. The campaign, named 'Operation Double Barrel,' highlights the risk of dual-use exploits in critical financial software supply chains. Read more

CISA Adds Two Actively Exploited Vulnerabilities to KEV Catalog

CISA has added CVE-2025-68686 (Fortinet FortiOS information exposure) and CVE-2026-16812 (Arista VeloCloud Orchestrator command injection) to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation, reinforcing BOD 26-04 requirements for federal agencies and urging all organizations to prioritize patching. Read more

OpenAI Open-Sources Codex Security Toolchain for AI-Powered Code Scanning in CI/CD

OpenAI has released the command-line interface and TypeScript SDK for Codex Security as open-source software, enabling developers to scan local code and Git changes for vulnerabilities and integrate checks into pre-commit and CI workflows, though actual analysis relies on OpenAI cloud services and requires authentication via ChatGPT login or API key. Read more