top of page
Cyber Security Hub
Stay updated with the latest news on technology, cybersecurity, market reports
Featured News


Cybersecurity News Roundup (20.7 - 26.7): AI-powered attacks, data breaches and critical vulnerabilities
Stay updated with the latest cybersecurity news from Vietnam and around the world, including AI-powered attacks, data breaches, critical vulnerabilities, and emerging cyber threats affecting businesses.
Jul 27


Cybersecurity landscape in Vietnam – Q2/2026: Key risks and recommendations for businesses
An analysis of Vietnam’s cybersecurity landscape in Q2 2026, covering online fraud, data breaches, malware, AI-powered threats, and key recommendations for businesses.
Jul 23


Last week in cybersecurity (June 22–28): EVN scams alert, AI manipulation, and Linux root-exploiting vulnerability
Explore last week in cybersecurity (June 22–28): EVN warns of fake OTPs, AI agents tricked into executing malware, and the DirtyClone Root flaw. Read now!
Jun 29


Network maintenance for Startups: In-house or Outsourced?
Learn what a startup network maintenance solution should include, how to choose the right support model, and what to look for in a service provider.
Jul 25


Financial sector cybersecurity 2026: Decoding 6 cyberattack trends and proactive defense strategies
Decode 6 financial sector cybersecurity trends in 2026 from Darktrace & Visa. Discover how to combat ransomware and phishing with a 24/7 SOC platform from IPSIP experts!
Jul 7


IPSIP Vietnam Pentest services: Penetration Testing for businesses
IPSIP provides pentest services in Vietnam for websites, APIs, mobile applications, networks, and cloud environments, including reports, remediation consulting, and retesting.
Jul 2


Claude code, Gemini CLI and Codex vulnerabilities expose new CI/CD security risks
Security flaws affecting Claude Code, Gemini CLI and Codex show how AI coding agents can expose CI/CD pipelines, source code, credentials and enterprise systems.
4 days ago


Critical Zoom vulnerability: risk of computer takeover via a familiar feature
A critical chain of security vulnerabilities has recently been discovered in Zoom, allowing anyone in a meeting – whether a presenter or an attendee – to take control of other participants' computers.
6 days ago


OpenAI pauses some Astra activities over Critical Cybersecurity Risks
OpenAI restricted some Astra activities after preliminary evaluations could not rule out Critical cybersecurity capabilities, including zero-day exploitation.
Aug 10
24H movement


Apple warns iPhone users in 110 countries they were targeted by Spyware
Apple warns iPhone users in 110 countries they were targeted by mercenary spyware. Learn what the alert means and how businesses should respond.
2 hours ago


Identity and Access Management (IAM): From paper policies to real-world execution
IAM compliance goes beyond policy documents, requiring precise enforcement across all users, applications, and infrastructure.
23 hours ago


DDoS attacks surge, 935 incidents exceed 1 Tbps in the first half of 2026
Cloudflare recorded 935 DDoS attacks exceeding 1 Tbps in H1 2026, with Q2 up 519%. Enterprises should prioritize automated mitigation, DNS protection, and continuous monitoring
1 day ago
All posts


Apple warns iPhone users in 110 countries they were targeted by Spyware
Apple warns iPhone users in 110 countries they were targeted by mercenary spyware. Learn what the alert means and how businesses should respond.
2 hours ago


Identity and Access Management (IAM): From paper policies to real-world execution
IAM compliance goes beyond policy documents, requiring precise enforcement across all users, applications, and infrastructure.
23 hours ago


DDoS attacks surge, 935 incidents exceed 1 Tbps in the first half of 2026
Cloudflare recorded 935 DDoS attacks exceeding 1 Tbps in H1 2026, with Q2 up 519%. Enterprises should prioritize automated mitigation, DNS protection, and continuous monitoring
1 day ago


GitLab releases emergency patch for 13 security vulnerabilities: What you need to know
Source code management platform GitLab has officially released new security updates to address 13 vulnerabilities across its system.
4 days ago


Hackers mass attack Microsoft SharePoint servers after public PoC release
Shortly after proof-of-concept (PoC) tools were widely shared online, hacker groups quickly leveraged them to launch real-world attacks against Microsoft SharePoint servers.
4 days ago


Claude code, Gemini CLI and Codex vulnerabilities expose new CI/CD security risks
Security flaws affecting Claude Code, Gemini CLI and Codex show how AI coding agents can expose CI/CD pipelines, source code, credentials and enterprise systems.
4 days ago


Picus Blue Report 2026: Multi-million dollar defenses still miss quiet attacks
According to the annual Blue Report 2026 recently published by Picus Labs, the cybersecurity defense capabilities of enterprises are showing signs of recovery, but the truth behind these positive numbers hides many concerning vulnerabilities.
5 days ago


A vulnerability in LiteLLM drags 2,500 organizations into danger
Beginning with a vulnerability in an auxiliary tool, the supply chain attack targeting LiteLLM rapidly expanded, threatening numerous technology systems worldwide.
5 days ago


Red Hat ACM hit by critical CVE that could lead to cluster-admin access
CVE-2026-10090 in Red Hat ACM scores 9.9 CVSS and may allow users with edit permissions to escalate to cluster-admin. Enterprises should review RBAC.
5 days ago


Critical Zoom vulnerability: risk of computer takeover via a familiar feature
A critical chain of security vulnerabilities has recently been discovered in Zoom, allowing anyone in a meeting – whether a presenter or an attendee – to take control of other participants' computers.
6 days ago


Wave of scans target critical VMware vCenter vulnerabilities
Cybersecurity experts have recently detected a sharp surge in scanning activity targeting VMware vCenter systems. This serves as an early warning signal that threat actors are actively hunting for unpatched targets in preparation for dangerous intrusion attempts.
6 days ago


CVE-2026-64638: WordPress XSS2Shell flaw could lead to PHP code execution
WordPress patched CVE-2026-64638, a pre-auth reflected XSS flaw that could lead to PHP code execution when an administrator interacts with attacker-controlled content.
6 days ago


Risk of enterprise data leakage from "one-click" vulnerability on Atlassian Rovo AI
The discovery of RovoBlast - a severe security vulnerability in the Atlassian Rovo AI assistant serves as proof that an enterprise's internal data can be exfiltrated through a single malicious link.
7 days ago


Levi Strauss data breach: 3 employee computers accessed via social engineering
Levi Strauss & Co. said it identified a cybersecurity incident in which an unauthorized third party used social engineering to gain access to three company-issued employee computers. From those devices, certain corporate information was accessed and exfiltrated.
Aug 11


What to do when Metabase faces a critical Zero-Day vulnerability?
Metabase has confirmed a critical cybersecurity incident involving an actively exploited zero-day vulnerability.
Aug 10


OpenAI pauses some Astra activities over Critical Cybersecurity Risks
OpenAI restricted some Astra activities after preliminary evaluations could not rule out Critical cybersecurity capabilities, including zero-day exploitation.
Aug 10


Demystifying IDS and IPS: A powerful security shield for enterprise networks
Two familiar yet crucial defensive tools that every organization must thoroughly understand are IDS (Intrusion Detection System) and IPS (Intrusion Prevention System).
Aug 7


Vulnerability in Cursor, VS Code, and Antigravity could steal API keys
A flaw in Cursor, VS Code, and Antigravity could execute commands after one click, putting API keys, source code, and developer devices at risk.
Aug 7


Meta AI model accidentally infiltrates external system due to testing configuration error
During a recent information security assessment, an artificial intelligence (AI) model from Meta unexpectedly gained access to the internet and infiltrated the computer system of a third-party service.
Aug 6


SMOKE#SCREEN Campaign: Impersonating Zoom and Adobe updates to hijack computers
Information security researchers have recently discovered a dangerous cyberattack campaign named SMOKE#SCREEN. By spreading fake software update notifications from familiar applications like Zoom or Adobe, attackers can silently install remote control tools and gain full control over victims' computers.
Aug 6
bottom of page
