top of page
Cyber Security Hub
Stay updated with the latest news on technology, cybersecurity, market reports
Featured News


Cybersecurity News Roundup (20.7 - 26.7): AI-powered attacks, data breaches and critical vulnerabilities
Stay updated with the latest cybersecurity news from Vietnam and around the world, including AI-powered attacks, data breaches, critical vulnerabilities, and emerging cyber threats affecting businesses.
Jul 27


Cybersecurity landscape in Vietnam – Q2/2026: Key risks and recommendations for businesses
An analysis of Vietnam’s cybersecurity landscape in Q2 2026, covering online fraud, data breaches, malware, AI-powered threats, and key recommendations for businesses.
Jul 23


Last week in cybersecurity (June 22–28): EVN scams alert, AI manipulation, and Linux root-exploiting vulnerability
Explore last week in cybersecurity (June 22–28): EVN warns of fake OTPs, AI agents tricked into executing malware, and the DirtyClone Root flaw. Read now!
Jun 29


Network maintenance for Startups: In-house or Outsourced?
Learn what a startup network maintenance solution should include, how to choose the right support model, and what to look for in a service provider.
Jul 25


Financial sector cybersecurity 2026: Decoding 6 cyberattack trends and proactive defense strategies
Decode 6 financial sector cybersecurity trends in 2026 from Darktrace & Visa. Discover how to combat ransomware and phishing with a 24/7 SOC platform from IPSIP experts!
Jul 7


IPSIP Vietnam Pentest services: Penetration Testing for businesses
IPSIP provides pentest services in Vietnam for websites, APIs, mobile applications, networks, and cloud environments, including reports, remediation consulting, and retesting.
Jul 2


Fortinet acquires Virtue AI to Expand Security from Networks to AI Agents
Fortinet acquires Virtue AI to extend continuous AI protection with red teaming, runtime guardrails and AI Agent governance for enterprise environments.
1 day ago


Jewelbug's multi-target attack campaign: When professional hackers scam crypto using AI
We often classify hackers into two distinct groups: cyber spies targeting state secrets on one side, and cybercriminals seeking financial gain on the other. However, a threat actor group known as Jewelbug (believed to be based in China) represents a unique exception.
2 days ago


Claude code, Gemini CLI and Codex vulnerabilities expose new CI/CD security risks
Security flaws affecting Claude Code, Gemini CLI and Codex show how AI coding agents can expose CI/CD pipelines, source code, credentials and enterprise systems.
Aug 14
24H movement


Alert: Hackers can now bypass MFA without using malware
By tampering with the login process, attackers gained access to the mailbox and redirected vendor payments. Notably, this campaign used no malware, infostealers, or remote access tools on the victim's device.
10 hours ago


Over 3.7 million patients impacted in CareCloud data breach
The CareCloud data breach – involving a U.S.-listed healthcare technology solutions provider – is turning into one of the largest healthcare data breaches of 2026.
11 hours ago


Attackers can modify or delete GitLab projects without logging In
GitLab patched CVE-2026-19478, a CVSS 9.4 GraphQL flaw that can allow unauthenticated attackers to modify or delete public projects remotely.
13 hours ago
All posts


ARToken emerges: new phishing toolkit targets Microsoft 365, steals tokens without passwords
Researchers have uncovered ARToken, a phishing toolkit abusing Microsoft 365 OAuth Device Code Flow to steal access tokens without passwords. Learn how it works and how to stay protected
Jul 6


Next-generation ransomware: When AI paves the way for browser attacks
The rapid evolution of Artificial Intelligence (AI) is completely reshaping the cybersecurity landscape, bringing both unprecedented opportunities and challenges.
Jul 3


Apple Hide My Email vulnerability could expose users' real email addresses
A vulnerability affecting Apple's Hide My Email feature could allow attackers to uncover the real email address behind an anonymized alias. According to reports, the issue was disclosed to Apple more than a year ago but remains unpatched. Independent testing by 404 Media also confirmed that the flaw was still exploitable at the time of publication.
Jul 3


Warning: Over 5 billion iPhone and Android devices face risk of covert attacks
Transferring images, videos, or documents between phones and computers has now become incredibly simple thanks to AirDrop on Apple devices or Quick Share on Android and Windows operating systems. However, this very convenience is inadvertently opening a loophole for cyberattacks, threatening the safety of more than 5 billion devices worldwide.
Jul 3


Warning on the threats of Shadow AI: a new attack technique targeting AI coding assistants
Instead of planting malware directly, the attacker cleverly inserts hidden instructions to trick autonomous AI assistants like Claude Code into automatically triggering remote destructive commands. This vulnerability is the clearest evidence of the dangers of Shadow AI.
Jul 2


Nissan confirms employee data breach following Oracle PeopleSoft zero-day attack
Nissan has confirmed that current and former employee data may have been accessed after attackers exploited the Oracle PeopleSoft zero-day vulnerability, CVE-2026-35273. According to Oracle, the campaign affected hundreds of companies, while Mandiant said it notified more than 100 organizations impacted by the attacks.
Jul 2


Security advisory: Two new Apache Tomcat vulnerabilities threaten network security
The Apache Software Foundation (ASF) has recently identified and disclosed two notable security vulnerabilities within Apache Tomcat, a widely used web server component.
Jul 2


A severe Microsoft Excel vulnerability poses a threat to Microsoft 365 and Office users
Một lỗ hổng CVE nghiêm trọng trong Microsoft Excel đang được cảnh báo vì có thể bị khai thác thông qua tệp bảng tính độc hại. Theo thông tin từ Microsoft và các nguồn cảnh báo bảo mật, lỗ hổng được định danh là CVE-2025-60727, thuộc nhóm thực thi mã từ xa trong hệ sinh thái Office.
Jul 1


US coordinates major takedown of illegal World Cup 2026 streaming websites
The excitement of the World Cup 2026 finals is not only electrifying football pitches but has also become the focal point of large-scale cybersecurity operations.
Jul 1


The dark side of World Cup 2026: A wave of high-tech crime besieges the football tournament
The latest security reports show that international cybercrime organizations had quietly constructed, orchestrated, and deployed a massive phishing infrastructure months before the opening whistle blew.
Jul 1


RedAmon: A new frontier in AI-powered Penetration Testing automation
The emergence of RedAmon, a new open-source cybersecurity platform, is bringing a fresh perspective to this workflow.
Jun 30


Does using a VPN make you impossible to hack? A comprehensive analysis of enterprise security boundaries
Does using a VPN make you impossible to hack? Learn about the protection VPN offers, its limitations against malware, phishing, and ransomware, and why businesses need Zero Trust, EDR, and SOC for comprehensive protection.
Jun 30


Warning: AI coding agents can be compromised through “clean” GitHub repositories
Security researchers from Mozilla's Zero Day Investigative Network (0DIN) have uncovered a sophisticated attack technique that targets AI coding agents through seemingly clean GitHub repositories.
Jun 30


Cybersecurity in Vietnam Q1/2026: Data becomes the primary target for cybercriminals
Cybersecurity in Vietnam Q1/2026 recorded 165 data breaches, over 473 million leaked records, alongside surging DDoS and APT attacks. Complete overview of trends and enterprise recommendations.
Jun 29


Cybersecurity incident at iPhone manufacturing plant: Alleged leak of over 630GB of Apple and Tesla data
A severe cyberattack targeting an Apple manufacturing partner in India has resulted in a massive breach of internal data.
Jun 29


Microsoft warns of phishing campaign targeting hotels with Node.js implant
Since April 2026, a sophisticated phishing campaign has been targeting hotels across Asia and Europe. The attackers abuse trusted services including Calendly and Google to distribute a ZIP archive containing the TonRAT malware, which is executed through the legitimate Node.js v24.13.0 runtime
Jun 29


Impersonating EVN to send OTP messages for account hijacking
Vietnam Electricity (EVN) has just issued an urgent warning regarding a newly emerged tech-based scam method. Malicious actors are exploiting the identity of the power sector to send fraudulent messages aimed at misappropriating citizens' data and assets.
Jun 26


Warning: Curl issues emergency patch for 18 critical vulnerabilities
Curl 8.21.0 addresses a record-breaking 18 security vulnerabilities (CVEs), the highest number ever fixed in a single Curl release. Among them is CVE-2026-8932, a flaw that originated in 2001 and remained undiscovered for more than 25 years before finally being patched.
Jun 26


Edgecution malware turns Microsoft Edge extension into a system backdoor
Researchers at Zscaler ThreatLabz have discovered an Edgecution malware campaign that spreads through Microsoft Teams and a malicious Microsoft Edge browser extension. The malware uses a two-component architecture and abuses Chrome Native Messaging to escape the browser sandbox, allowing attackers to execute commands, run PowerShell scripts, and gain direct access to victims' systems.
Jun 26


Alert: new vulnerabilities in AI ecosystem threaten enterprise cybersecurity
In June 2026, security researchers identified a verification flaw on ClawHub that enabled 15 unauthorized accounts to publish 23 deceptive plugins using official OpenClaw namespaces.
Jun 25
bottom of page
