Cyber Threat Intelligence

Global coverage · Asia-Pacific focus — September 7, 2026
6
Active Threats
4
Incidents (7d)
6
Critical CVEs
8
APT Groups
Critical High Medium Low
Executive Summary
The current threat picture is dominated by rapid, large-scale exploitation of internet-facing edge and management infrastructure, with CISA adding fifteen vulnerabilities to the KEV catalogue between 11 August and 4 September 2026, including a maximum-severity SonicWall SMA 1000 chain (CVE-2026-83548/83549) and an actively exploited Chromium V8 type-confusion flaw (CVE-2026-85046). Adversary tradecraft is measurably shifting toward abuse of the software and AI supply chain: the JetBrains Cadence breach via unpatched TeamCity (CVE-2026-63077) exposed AWS credentials and customer source code, while Chinese-speaking operators behind the SecFlow campaign orchestrated commercial AI models as interchangeable components to conduct intrusions against Taiwanese, Indonesian and Vietnamese targets. China-nexus espionage remains the principal strategic threat to the Asia-Pacific, evidenced by Operation QUICSILVER against Myanmar government and IT entities and the FBI's August disruption of the MSS/PLA-contracted QTFY proxy infrastructure. North Korean operations continue to bifurcate into technical intrusion, with the Rapid7-reported ted Linux backdoor implanted in trojanised HAProxy binaries at South Korean firms, and revenue-generating employment fraud now expanding beyond IT into healthcare, sales and finance roles.
Sources
25 web sources analyzed
Active Threats 6 campaigns
SonicWall SMA 1000 Zero-Day Exploitation Chain CRITICAL Edge Device Exploitation
Threat actors are chaining CVE-2026-83548, a CVSS 10.0 pre-authentication server-side request forgery in the SMA 1000 WorkPlace interface, with CVE-2026-83549, an OS command injection in the Appliance Management Console, to achieve remote code execution on internet-facing VPN concentrators. SonicWall confirmed active in-the-wild exploitation and CISA added both flaws to the KEV catalogue on 2 September 2026 with a 5 September remediation deadline. SMA 1000 appliances are widely deployed as remote-access gateways for mid-market and government organisations across the Asia-Pacific.
Attribution: Unattributed; tradecraft consistent with access brokers and ransomware affiliates that historically weaponise SSL-VPN flaws Targets: United States, Australia, Germany, Japan, Singapore
SecFlow AI-Orchestrated Intrusion Framework HIGH State-Sponsored Cyber Espionage
Hunt.io documented a Chinese-speaking operator set running the SecFlow framework across five exposed directories, routing requests to Claude, Qwen and DeepSeek through private proxies on the niestools.com domain to semi-automate reconnaissance, exploitation and credential harvesting. Confirmed impact includes 822 compromised office-automation user records and 1.28GB of exfiltrated data, with targeting of Kuomintang political archives in Taiwan and the Indonesian Ministry of Foreign Affairs. The campaign was reported on 4 September 2026 and follows a comparable June 2026 operation.
Attribution: Chinese-speaking state-sponsored operators (moderate confidence) Targets: Taiwan, Indonesia, Vietnam, China, Thailand, Afghanistan
DPRK Employment and Identity Fraud Operations HIGH Insider Threat / Financially Motivated Fraud
North Korean operators have expanded remote-worker infiltration beyond software engineering into healthcare, biotechnology, sales, staffing and financial services roles. One cluster tracked as PurpleDelta applied to more than 1,100 companies using 22 fabricated personas at a rate of roughly 60 applications daily, employing Astrill VPN, IPRoyal proxies, PiKVM hardware and AI transcription tools to defeat interview and onboarding controls. Approximately USD 1.97 million transited sanctioned entities between December 2025 and February 2026.
Attribution: North Korea (Famous Chollima, Jasper Sleet, Nickel Tapestry, UNC5267, Wagemole); operators assessed to be physically based in China Targets: United States, Australia, South Korea, Japan, Singapore
StyleSmuggler Magento / Adobe Commerce Zero-Day CRITICAL Web Application Zero-Day
Sansec disclosed an unpatched flaw affecting Magento Open Source 2.4.6 through 2.4.9 and Adobe Commerce, in which attackers inject PHP into files written by the platform and trigger execution through the routine Payment Transaction Failed Reminder email rendering path, requiring no user interaction. The resulting implant masquerades as the Linux kernel thread [kworker/u:8:0], installs outside the web root and re-establishes cron persistence every five minutes. Exploitation began 4 September 2026 with no vendor patch or CVE assigned as of 6 September.
Attribution: Unattributed; consistent with organised e-commerce skimming and Magecart-class actors Targets: Global, Netherlands, United States, Australia, Japan
Citrix NetScaler Authentication Bypass Exploitation Wave HIGH Edge Device Exploitation
CVE-2026-19490 allows unprivileged remote attackers to bypass authentication on NetScaler ADC and Gateway appliances configured as AAA virtual servers or gateways, depending on firmware version and SAML Action configuration. Previdian sensors recorded requests matching public proof-of-concept code from three distinct source IPs geolocated to Australia, the United States and Germany on 3 September 2026, and Belgium's national cyber centre issued a parallel warning. Over 22,000 NetScaler appliances remain internet-exposed.
Attribution: Unattributed opportunistic exploitation following public PoC release Targets: Australia, United States, Germany, Belgium
MikroTik RouterOS 'MikroTrick' Router Hijacking HIGH Network Infrastructure Compromise
CERT Polska warned on 5 September 2026 that attackers are chaining two RouterOS vulnerabilities, collectively dubbed MikroTrick, against internet-exposed SSH services to obtain full administrative control without authentication. Successful compromises have been observed since at least 2 September 2026, with a hallmark indicator being creation of an SSH user named '-2'. MikroTik has issued fixes in RouterOS 7.24.2, 7.23.5 and 6.49.21; consumer devices retaining default firewall rules are not exposed.
Attribution: Unattributed; router compromise at scale is typically a precursor to proxy or botnet infrastructure build-out Targets: Poland, Global
APT Tracker
Group Attribution Recent Activity TTPs
QTFY
Nanjing Xinjiuwei Network Technology Company
China The FBI announced in August 2026 the court-authorised seizure of hard-coded domains qt-proxy[.]org, qtproxy[.]xyz and securelink.qtproxy[.]xyz, disab… T1595.002 - Active Scanning: Vulnerability Scanning T1190 - Exploit Public-Facing Application T1505.003 - Server Software Component: Web Shell T1090.003 - Proxy: Multi-hop Proxy
APT37
Lazarus-adjacent clusters, Kimsuky-adjacent clusters, Reaper, ScarCruft
North Korea Rapid7 Labs published research on 4 September 2026 detailing a previously undocumented Linux toolkit, comprising the 'ted' backdoor and a companion '… T1554 - Compromise Host Software Binary T1195.002 - Supply Chain Compromise: Compromise Software Supply Chain T1071.001 - Application Layer Protocol: Web Protocols T1070.002 - Indicator Removal: Clear Linux or Mac System Logs
Operation QUICSILVER Actor
QUICAgent operator, COOLCLIENT-linked cluster
China Seqrite Labs reported on 24 August 2026 a China-nexus campaign first observed in April 2026, with additional artefacts recovered in June and July 202… T1566.001 - Phishing: Spearphishing Attachment T1204.002 - User Execution: Malicious File T1218 - System Binary Proxy Execution T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
SilkParasite
BLOODALCHEMY operator, Deed RAT cluster
China Bitdefender Labs disclosed on 19 August 2026 a previously unreported espionage operation, first identified in late 2025 and ongoing through August 20… T1566.001 - Phishing: Spearphishing Attachment T1574.002 - Hijack Execution Flow: DLL Side-Loading T1027 - Obfuscated Files or Information T1102.002 - Web Service: Bidirectional Communication
Mirage Kitten
NodeRabbit operator, PollCat cluster
Iran Kaspersky reported on 3 September 2026 an Iran-linked campaign using fabricated LinkedIn recruiter personas to distribute trojanised React coding ass… T1566.002 - Phishing: Spearphishing Link T1656 - Impersonation T1204.002 - User Execution: Malicious File T1573.001 - Encrypted Channel: Symmetric Cryptography
Vulnerability Alerts
CVE-2026-83548
CRITICAL
SonicWall SMA 1000 series appliances (WorkPlace interface)
Server-side request forgery rated CVSS 10.0 permitting unauthenticated remote access to sensitive appliance functionality. Chained with CVE-2026-83549 for full remote code execution. Added to the CISA KEV catalogue on 2 September 2026 with a 5 September remediation due date.
Exploited in the Wild · Patch: Yes
CVE-2026-83549
HIGH
SonicWall SMA 1000 series Appliance Management Console
OS command injection rated CVSS 7.8 allowing an attacker holding administrative privileges to execute arbitrary operating system commands. Used as the second stage of the actively exploited SMA 1000 zero-day chain. Added to the CISA KEV catalogue on 2 September 2026.
Exploited in the Wild · Patch: Yes
CVE-2026-85046
HIGH
Google Chrome / Chromium V8 JavaScript and WebAssembly engine, prior to 152.0.7977.82
Type confusion in V8 rated CVSS 8.8 enabling arbitrary code execution within the renderer sandbox via a crafted HTML page. This is the sixth actively exploited Chrome zero-day of 2026. Added to the CISA KEV catalogue on 4 September 2026 with a federal remediation deadline of 18 September 2026.
Exploited in the Wild · Patch: Yes
CVE-2026-63077
CRITICAL
JetBrains TeamCity CI/CD server
Deserialization flaw rated CVSS 9.8 permitting unauthenticated attackers to bypass authentication checks and execute arbitrary OS commands with the privileges of the TeamCity server process. Disclosed July 2026 and added to the CISA KEV catalogue on 5 August 2026; exploited between 8 and 24 August 2026 to breach JetBrains' own Cadence service.
Exploited in the Wild · Patch: Yes
CVE-2026-82329
CRITICAL
JFrog Artifactory (default configuration)
Improper authentication rated CVSS 9.8 that allows unauthenticated network-adjacent actors to obtain administrative privileges on the artifact repository. Given Artifactory's role as a build-artifact source of truth, successful exploitation carries direct software supply-chain consequences. Added to the CISA KEV catalogue on 2 September 2026.
Exploited in the Wild · Patch: Yes
CVE-2026-49869
CRITICAL
Kestra OSS workflow orchestration platform
OS command injection rated CVSS 10.0 exploited by unauthenticated attackers to establish reverse shells, enumerate Docker container environments and deploy XMRig cryptocurrency miners. Microsoft documented operators pivoting from compromised Kestra infrastructure to harvest LLM provider credentials. Added to the CISA KEV catalogue on 2 September 2026.
Exploited in the Wild · Patch: Yes
CVE-2026-81578
CRITICAL
PaperCut NG and PaperCut MF print management servers, all versions
Missing authentication for a critical function, chained with CVE-2026-82078 unsafe reflection to achieve remote code execution. Actively exploited for credential theft against educational institutions across the United States and Europe. Added to the CISA KEV catalogue on 31 August 2026.
Exploited in the Wild · Patch: Yes
CVE-2026-19490
CRITICAL
Citrix NetScaler ADC and NetScaler Gateway configured as AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy)
Authentication bypass allowing unprivileged remote attackers to circumvent authentication depending on firmware version and SAML Action configuration. Exploitation attempts matching public proof-of-concept code were observed from Australian, U.S. and German source IPs on 3 September 2026, with more than 22,000 appliances internet-exposed. Citrix issued fixed builds in mid-August 2026.
Exploited in the Wild · Patch: Yes
Country Cyber Posture
Country Threat Level Assessment Recent Incidents
China HIGH Assessed as the most prolific state sponsor of cyber espionage affecting the Asia-Pacific, operating through an MSS and PLA contractor ecosystem exemplified by QTFY. Chinese-nexus operators are visibly integrating commercial AI models into intrusion workflows, and domestic Chinese government, education and industrial hosts also appear as victims within the SecFlow dataset, indicating contested infrastructure and opportunistic collection.
FBI seizure of QTFY QTRouter and QTProxy infrastructure operated by Nanjing Xinjiuwei Network Technology Company (August 2026)
SecFlow AI-orchestrated campaign infrastructure attributed to Chinese-speaking operators (reported 4 September 2026)
North_Korea HIGH Continues a dual-track programme of technical intrusion for espionage and large-scale revenue generation through cryptocurrency theft and fraudulent remote employment. Tooling maturity is increasing, with purpose-built Linux implants embedded into trojanised infrastructure binaries rather than relying on vulnerability exploitation.
ted Linux backdoor and curlRAT compiled into trojanised HAProxy binaries at two South Korean organisations (Rapid7, 4 September 2026)
Expansion of DPRK job fraud into healthcare, biotechnology, sales and financial services roles (reported August 2026)
South_Korea HIGH Sustained target of North Korean state-sponsored collection against industrial, automotive and media sectors. The observed compromise of load-balancing infrastructure via trojanised HAProxy binaries indicates adversary presence at network chokepoints capable of intercepting traffic and harvesting credentials at scale, with a suspected groupware vendor supply-chain vector.
Two South Korean organisations in automotive and media sectors compromised via trojanised HAProxy 2.8.12 load balancers hosting the ted backdoor (disclosed 4 September 2026)
Suspected compromise of a domestic groupware vendor assessed as the initial access path for the ted toolkit
Taiwan HIGH Remains a priority collection target for China-nexus actors, with political and party-affiliated archives specifically targeted alongside government entities. Adversaries are demonstrating increased operational tempo through AI-assisted tooling that compresses reconnaissance-to-exploitation timelines.
SecFlow campaign targeting Kuomintang Party political archives, with GLUTTON webshell framework and ASPX web shells deployed (reported 4 September 2026)
Japan ELEVATED Exposure is presently driven more by mass exploitation of internet-facing enterprise software than by publicly attributed targeted intrusions in the reporting window. Large installed bases of Citrix NetScaler, SonicWall SMA and Adobe Commerce infrastructure place Japanese enterprises within the blast radius of several concurrent exploitation waves.
Broad regional exposure to the SonicWall SMA 1000 zero-day chain CVE-2026-83548 and CVE-2026-83549 (KEV, 2 September 2026)
Exposure to the unpatched StyleSmuggler Magento and Adobe Commerce zero-day affecting all current versions (from 4 September 2026)
India ELEVATED Indian research and vendor telemetry is central to regional attribution, with Seqrite Labs producing the Operation QUICSILVER analysis. Regional threat activity from China-nexus and Pakistan-adjacent clusters continues against government and technology targets, though no major India-specific intrusion was publicly confirmed in the immediate reporting window.
Seqrite Labs disclosure of Operation QUICSILVER, with adjacent targeting observed against Pakistan and Mongolia (24 August 2026)
Widespread regional exposure to actively exploited edge-device flaws including CVE-2026-19490 and CVE-2026-83548
Australia ELEVATED Notable both as a source of observed exploitation traffic and as a jurisdiction taking enforcement action against supply-chain compromise. Australian companies are also named among the targets of DPRK remote-worker infiltration alongside U.S. and EU firms.
Exploitation attempts against Citrix NetScaler CVE-2026-19490 observed from an Australian source IP (3 September 2026)
Two Western Australian men charged over the TeamPCP open-source supply-chain compromise affecting more than 1,000 organisations (Perth Magistrates Court, 27 August 2026)
Vietnam ELEVATED Directly identified within the SecFlow victim set, with industrial hosts compromised by Chinese-speaking operators. Vietnamese industrial and government networks remain a consistent focus of China-nexus collection in Southeast Asia.
Vietnamese industrial hosts compromised in the SecFlow AI-orchestrated campaign (reported 4 September 2026)
Singapore MODERATE No publicly confirmed nation-state intrusion against Singaporean entities was reported in the current window, but the city-state's density of regional financial and technology headquarters keeps it within the standing target set for China-nexus collection documented across Southeast Asia. Primary near-term risk is opportunistic exploitation of exposed VPN and management infrastructure.
Standing regional exposure to China-nexus espionage campaigns documented against Southeast Asian government and technology targets
Sector exposure to actively exploited edge-device and RMM vulnerabilities including CVE-2026-83548 and CVE-2026-86218
Philippines MODERATE No new publicly attributed intrusion was confirmed during the reporting window. The Philippines nonetheless remains within the established targeting scope of China-nexus espionage against Southeast Asian government and telecommunications entities, and exposure to the current wave of edge-device exploitation is material given regional deployment patterns.
Continued inclusion in documented China-nexus targeting of Southeast Asian government and telecommunications sectors
Exposure to the actively exploited SonicWall SMA 1000 and Citrix NetScaler flaws
Sector Threat Matrix
Government
CRITICAL
Government entities across the Asia-Pacific and Central Asia sustained the highest volume of confirmed state-sponsored intrusion in the reporting window, with China-nexus actors accounting for the majority of attributed activity. Adversaries are combining spearphishing with abuse of legitimate system binaries and increasingly with AI-assisted exploitation workflows.
  • Operation QUICSILVER QUICAgent backdoor against Myanmar government and IT bodies
  • SecFlow intrusions against Taiwanese political archives and the Indonesian Ministry of Foreign Affairs
  • SilkParasite five-RAT campaign against Central Asian governments
Technology
CRITICAL
Technology vendors are being targeted as force multipliers, with compromise of a single CI/CD or artifact platform yielding downstream access to large customer estates. The JetBrains Cadence breach and the TeamPCP prosecutions both illustrate a decisive shift toward developer-toolchain targeting.
  • CVE-2026-63077 TeamCity exploitation leading to the JetBrains Cadence breach and AWS credential theft
  • CVE-2026-82329 JFrog Artifactory unauthenticated administrative access
  • TeamPCP poisoning of Trivy, Checkmarx KICS and LiteLLM across GitHub Actions, Docker Hub, npm, PyPI and OpenVSX
Telecommunications
HIGH
Network infrastructure and voice platforms remain a priority for both state and criminal actors seeking persistent, traffic-visible positions. Exploitation of routing and PBX estate provides durable access and proxy capacity that is difficult for defenders to detect.
  • MikroTrick RouterOS exploitation chain granting unauthenticated administrative control since 2 September 2026
  • CVE-2026-9586 Sangoma Switchvox SQL injection, CVSS 9.3, added to KEV 2 September 2026
  • QTFY QTRouter proxy network built from compromised IoT and network devices
Financial Services
HIGH
Financial and fintech organisations face converging pressure from Iranian espionage tradecraft delivered through fraudulent recruitment and from DPRK revenue operations targeting cryptocurrency holdings and payroll systems. Social engineering aimed at developers and engineers is the dominant initial access vector.
  • Mirage Kitten NodeRabbit and PollCat implants delivered via fake LinkedIn coding assessments to fintech targets
  • DPRK fraudulent remote-worker placement into financial services and cryptocurrency firms
  • Cumulative DPRK cryptocurrency theft exceeding USD 6.75 billion, with USD 2.02 billion stolen in 2025
Defense Industrial Base
HIGH
Contractor-driven Chinese collection against defence-adjacent research and government agencies continued until the August 2026 disruption of QTFY infrastructure. Targeting of academic and research communities serves as an indirect route into defence programmes.
  • QTFY intrusions against U.S. federal agencies and global research institutions through June 2026
  • SilkParasite targeting of Central Asian government and security bodies
  • Exploitation of edge VPN appliances as the standard initial access vector into segmented environments
Energy & Utilities
HIGH
Russian sabotage-oriented tradecraft remains the defining risk, with destructive wiper capability demonstrated against European energy infrastructure and continued pre-positioning by China-linked actors in utility networks via edge devices. IT/OT boundary segmentation remains the critical control gap.
  • Sandworm/APT44 DynoWiper deployment against Poland's energy sector, attributed by ESET with medium confidence
  • Volt Typhoon living-off-the-land pre-positioning in utility networks, with SYLVANITE initial access via edge devices
  • Sustained targeting of misconfigured VPNs and network edge devices across North America and Europe
Healthcare
ELEVATED
Healthcare is now exposed on two distinct fronts: conventional data theft, including protected health information exfiltrated during the SecFlow campaign, and DPRK employment fraud that has expanded explicitly into healthcare and biotechnology hiring. Identity assurance in remote onboarding is the emerging control weakness.
  • Patient health information included within the 1.28GB exfiltrated in the SecFlow campaign
  • DPRK fraudulent applicants targeting healthcare and biotechnology roles
  • Ransomware pressure from Qilin and Akira, which together with LockBit and The Gentlemen account for 41% of claimed victims
Manufacturing
ELEVATED
Manufacturing and automotive firms in Northeast Asia are under sustained DPRK collection pressure aimed at intellectual property and supply-chain intelligence. Adversary persistence inside network appliances rather than endpoints complicates detection and eviction.
  • ted backdoor implanted in HAProxy load balancers at a South Korean automotive organisation
  • SecFlow targeting of industrial hosts in Vietnam and China
  • Ransomware groups Qilin, Akira and Play leveraging VPN compromise for rapid encryption of production networks
Cyber News Feed Last 7 days
Incident Log Last 30 days
North Korean 'ted' Linux Backdoor Found Inside Trojanised HAProxy at South Korean Firms HIGH Espionage
Rapid7 Labs disclosed a previously undocumented Linux toolkit compiled directly into trojanised HAProxy 2.8.12 load bal…
Sep 4, 2026 North Korea (APT37, with Lazarus and Kimsuky cluster overlap; medium confidence)
SecFlow Campaign Uses Commercial AI Agents Against Taiwanese and Indonesian Government Targets HIGH Espionage
Hunt.io researchers documented Chinese-speaking operators running the SecFlow framework across five exposed directories…
Sep 4, 2026 China (Chinese-speaking state-sponsored operators)
Unpatched StyleSmuggler Zero-Day Exploited Across Magento and Adobe Commerce Stores CRITICAL Other
Dutch security firm Sansec disclosed active exploitation, beginning 4 September 2026, of an unpatched flaw affecting Ma…
Sep 4, 2026 Unattributed
Google Patches Sixth Actively Exploited Chrome Zero-Day of 2026 HIGH Other
Google released an emergency Chrome update addressing CVE-2026-85046, a CVSS 8.8 type confusion vulnerability in the V8…
Sep 4, 2026 Unattributed; browser zero-days of this class are historically associated with commercial spyware vendors and state-aligned actors
Citrix NetScaler Authentication Bypass CVE-2026-19490 Under Active Attack HIGH Other
Security firm Previdian reported that on 3 September 2026 one of its NetScaler sensors received requests matching publi…
Sep 3, 2026 Unattributed
Iran-Linked Mirage Kitten Delivers NodeRabbit and PollCat via Fake LinkedIn Coding Tests MEDIUM Phishing
Kaspersky reported on 3 September 2026 that the Iran-linked Mirage Kitten group is using fabricated LinkedIn recruiter …
Sep 3, 2026 Iran (Mirage Kitten; high confidence per Kaspersky)
SonicWall SMA 1000 Zero-Day Chain Exploited for Remote Code Execution CRITICAL Other
SonicWall disclosed that threat actors are chaining two previously unknown vulnerabilities in SMA 1000 remote-access ap…
Sep 2, 2026 Unattributed
MikroTik RouterOS 'MikroTrick' Chain Exploited to Hijack Internet-Exposed Routers HIGH Other
CERT Polska published a warning on 5 September 2026 that attackers are combining two MikroTik RouterOS vulnerabilities,…
Sep 2, 2026 Unattributed
PaperCut NG/MF Zero-Days Exploited for Credential Theft Against Schools HIGH Data Breach
Attackers chained CVE-2026-81578, a missing authentication for a critical function, with CVE-2026-82078, an unsafe refl…
Aug 31, 2026 Unattributed
SafePay Ransomware Claims Air Liquide Korea HIGH Ransomware
The SafePay ransomware group listed industry.airliquide.kr, the Korean industrial-gases arm of Air Liquide, on its leak…
Aug 25, 2026 SafePay ransomware group
Krybit Ransomware Publishes 114GB from Singapore Clinic Group HIGH Ransomware
A private primary healthcare group operating 11 clinics across Singapore was compromised by the Krybit ransomware opera…
Aug 21, 2026 Krybit ransomware group
Gunra Ransomware Steals 150GB from Indonesian Agri-Biotech Manufacturer MEDIUM Ransomware
An Indonesian agricultural biotechnology and fertilizer manufacturing company was claimed by the Gunra ransomware group…
Aug 21, 2026 Gunra ransomware group
Quest Aparthotel Chain Exposes Guest PII via Third-Party Breach MEDIUM Data Breach
Australian aparthotel chain Quest, which operates more than 120 properties across Australia, New Zealand and Fiji, disc…
Aug 17, 2026
Philippine SMS Provider Breach Allegedly Exposes 160 Million Messages HIGH Data Breach
A Philippine SMS/telecommunications provider was reported compromised in August 2026, with threat actors alleging expos…
Aug 14, 2026
AI-Driven Autonomous Cyberattack Hits Taiwan Government Systems CRITICAL APT Campaign
Taiwan's Ministry of Digital Affairs confirmed that government agencies were targeted in July by what researchers at Is…
Aug 12, 2026 Suspected China-linked actors (AI-agent assisted)