Monitoring TWCERT/CC TVN (English) vulnerability notes for Taiwan vendor exposure

This evergreen playbook guides global security, cloud, and operations teams in using the TWCERT/CC English TVN RSS feed to monitor Taiwan-specific vulnerability disclosures and assess vendor exposure. It provides practical, source-grounded steps for integrating this feed into vulnerability management workflows without implying real-time alerts or prescribing rigid schedules. Read more

What to capture from a ransomware leak post before sharing internally

This checklist guides security teams on how to responsibly capture and verify key details from ransomware leak posts before internal sharing, including timestamps, claimed victims, proof files, and validation steps, while avoiding amplification of unverified claims. It supports East Asia cyber risk monitoring by promoting disciplined handling of dark-web intelligence. Read more

Map AI misuse and model abuse signals to MITRE ATLAS without hype

This tutorial guides East Asia-facing security teams on how to map observed AI misuse and model abuse signals to MITRE ATLAS techniques using a structured, uncertainty-aware approach. It emphasizes separating public facts from speculation, assigning clear ownership, and establishing flexible review workflows without relying on numeric thresholds or rigid escalation rules. Read more

SLSA questions to ask when a supplier claims ‘secure build pipeline’

Use the SLSA framework to evaluate supplier build integrity through neutral questions on provenance, signing, reproducibility, dependency pinning, and evidence artifacts—without accepting marketing claims as proof. This checklist supports East Asia-facing security, cloud, and supply-chain teams in verifying supplier assertions. Read more

Building an Internal Patch-SLA Queue from Korea KISA/KrCERT Vulnerability Notices: A Practical Workflow Guide

Organizations can transform Korea KISA/KrCERT vulnerability notices into an auditable internal patch-SLA workflow by establishing clear triage steps, ownership rules, severity interpretation, exception tracking, and integration with existing vulnerability management systems—without imposing rigid thresholds or inventing unsupported procedures. Read more

Map an East Asia incident write-up to MITRE ATT&CK without overclaiming

This tutorial guides security teams in East Asia and globally on how to map public incident reports to MITRE ATT&CK techniques while preserving uncertainty, avoiding unwarranted attribution, and maintaining evidence traceability. It provides step-by-step workflow guidance for analysts, threat intel teams, and incident responders to use ATT&CK as a neutral taxonomy for structuring findings without inflaming confidence beyond what the source supports. Read more