East Asia Cyber Risk Signal: What Security Teams Should Monitor

Threat actors are actively exploiting CVE-2026-55040, a critical Microsoft SharePoint authentication bypass vulnerability, following the release of a public proof-of-concept by Rapid7. The flaw allows unauthenticated remote attackers to forge JWT tokens and impersonate any SharePoint user, including administrators, to read and modify data. Microsoft patched the vulnerability in its July 2026 Update Tuesday release. Organizations must prioritize patching and monitor for anomalous authentication patterns in SharePoint environments. Read more

GovCERT.HK Alert Highlights OpenSSL Denial-of-Service Flaw CVE-2026-14456 Across Major Release Lines

GovCERT.HK has issued Security Alert A26-08-24 warning of a denial-of-service vulnerability in OpenSSL versions 3.5.x, 3.6.x, and 4.0.x, patched in releases 3.5.8, 3.6.4, and 4.0.2. Tracked as CVE-2026-14456, the flaw poses availability risks to global infrastructure relying on OpenSSL for TLS, with particular relevance to East Asia’s high-density financial, telecom, and cloud environments. The alert, published August 14, 2026, follows the upstream OpenSSL advisory by one day, underscoring the role of regional CERTs in accelerating patch awareness. Read more

Dream Security Details Chinese Hackers’ Eight-Agent AI Attack Framework Targeting Taiwan Government Systems

An Israeli AI security startup disclosed that Chinese threat actors deployed an autonomous AI attack framework utilizing eight concurrent AI agents to breach Taiwan government networks, featuring dual-layer Bayesian decision-making, self-correction of false positives, and cross-agent validation of vulnerabilities. Read more

Cisco ASA and FTD Flaw Exploited in the Wild Triggers Remote DoS

Cisco has confirmed active exploitation of CVE-2026-20349 (CVSS 8.6), a high-severity vulnerability in ASA and FTD software allowing unauthenticated remote attackers to trigger device reload via crafted HTTP requests to SSL VPN services, resulting in denial-of-service. The flaw affects multiple versions of ASA and FTD with specific VPN configurations enabled, and has been added to CISA’s KEV catalog with a patch deadline of August 14, 2026 for U.S. federal agencies. No workarounds exist; mitigation requires applying vendor-provided hotfixes. Read more

ASEC Weekly Report Highlights DragonForce, Qilin, and ShinyHunters Activity Across Education, Manufacturing, and Healthcare Sectors in August 2026

ASEC’s August 12, 2026 threat report details ransomware attacks by DragonForce on a Korean online education provider and Qilin on a Korean motor/robotics manufacturer, alongside ShinyHunters’ data theft claim against a U.S. digital healthcare firm, reflecting ongoing regional ransomware trends targeting critical sectors in East Asia and North America. Read more

Taiwan Formalizes Tiered ICT Security for Official Travel to Mitigate Espionage Risks

Taiwan's Administration for Cyber Security (ACS) has issued binding guidelines mandating tiered ICT security measures for government personnel traveling abroad, requiring temporary, sanitized devices and data minimization for officials visiting high-risk jurisdictions including mainland China, Hong Kong, and Macau to prevent espionage and data compromise. Read more

Fairis: A Provable Defense Against Fairness Poisoning in Collaborative Machine Learning

Fairis introduces a server-side reweighting scheme that provably reduces adversarial influence in collaborative ML by weighting client updates based on local fairness scores, offering monotone weight reduction against bias while maintaining positive weights for honest participants, with empirical validation on Taiwan Credit data showing 41–54% weight reduction for stealthy adversaries. Read more