top of page
Cyber Security Hub
Stay updated with the latest news on technology, cybersecurity, market reports
Featured News


Cybersecurity Weekly News (September 7–13): Scam Warnings, Tighter Data Protection and AI Agent Attacks
Cybersecurity news for September 7–13, 2026: scam warnings, tighter data protection, Cisco FMC exploitation and AI Agent attacks on PaperCut.
3 days ago


IPSIP Vietnam attends HCMC K-Brand Expo 2026, expanding Vietnam - Korea business and technology connections
IPSIP Vietnam attended HCMC K-Brand Expo 2026 in Ho Chi Minh City on August 27, connecting with South Korean businesses and expanding opportunities for collaboration in technology, cybersecurity, and IT.
Aug 28


Cybersecurity News Roundup (20.7 - 26.7): AI-powered attacks, data breaches and critical vulnerabilities
Stay updated with the latest cybersecurity news from Vietnam and around the world, including AI-powered attacks, data breaches, critical vulnerabilities, and emerging cyber threats affecting businesses.
Jul 27


Optimizing IT risk management with in-depth Information Security GRC solutions
Information security GRC is increasingly becoming a critical part of IT governance strategy, helping align governance, risk, and compliance requirements into a unified model.
Aug 25


Network maintenance for Startups: In-house or Outsourced?
Learn what a startup network maintenance solution should include, how to choose the right support model, and what to look for in a service provider.
Jul 25


Financial sector cybersecurity 2026: Decoding 6 cyberattack trends and proactive defense strategies
Decode 6 financial sector cybersecurity trends in 2026 from Darktrace & Visa. Discover how to combat ransomware and phishing with a 24/7 SOC platform from IPSIP experts!
Jul 7


AI-Assisted Cyber Attacks Are Lowering the Technical Barrier for Hackers
AI is helping hackers automate reconnaissance, exploitation, and data processing. Learn what this means for businesses and which defenses matter most in 2026.
13 hours ago


Warning on AI-powered phishing campaign targeting Microsoft Cloud accounts
Microsoft has issued an urgent alert regarding two highly sophisticated cyberattack campaigns targeting enterprise users. The danger of these AI-powered phishing campaigns lies in their direct targeting of the human factor, psychologically manipulating victims into handing over control themselves.
2 days ago


AI Agents Can Now Execute Multiple Steps Across the Cyberattack Chain
AI agents can automate reconnaissance, exploitation, credential theft, and other attack stages with less human intervention, changing cyber risk for businesses.
2 days ago
24H movement


AI-Assisted Cyber Attacks Are Lowering the Technical Barrier for Hackers
AI is helping hackers automate reconnaissance, exploitation, and data processing. Learn what this means for businesses and which defenses matter most in 2026.
13 hours ago


Warning on AI-powered phishing campaign targeting Microsoft Cloud accounts
Microsoft has issued an urgent alert regarding two highly sophisticated cyberattack campaigns targeting enterprise users. The danger of these AI-powered phishing campaigns lies in their direct targeting of the human factor, psychologically manipulating victims into handing over control themselves.
2 days ago


AI Agents Can Now Execute Multiple Steps Across the Cyberattack Chain
AI agents can automate reconnaissance, exploitation, credential theft, and other attack stages with less human intervention, changing cyber risk for businesses.
2 days ago
All posts


CVE-2026-64638: WordPress XSS2Shell flaw could lead to PHP code execution
WordPress patched CVE-2026-64638, a pre-auth reflected XSS flaw that could lead to PHP code execution when an administrator interacts with attacker-controlled content.
Aug 12


Risk of enterprise data leakage from "one-click" vulnerability on Atlassian Rovo AI
The discovery of RovoBlast - a severe security vulnerability in the Atlassian Rovo AI assistant serves as proof that an enterprise's internal data can be exfiltrated through a single malicious link.
Aug 11


Levi Strauss data breach: 3 employee computers accessed via social engineering
Levi Strauss & Co. said it identified a cybersecurity incident in which an unauthorized third party used social engineering to gain access to three company-issued employee computers. From those devices, certain corporate information was accessed and exfiltrated.
Aug 11


What to do when Metabase faces a critical Zero-Day vulnerability?
Metabase has confirmed a critical cybersecurity incident involving an actively exploited zero-day vulnerability.
Aug 10


The hybrid model: Combining IT outsourcing with outsourced SOC services
Learn how combining IT outsourcing and cybersecurity with an outsourced SOC helps enterprises define responsibilities and improve IT–SOC collaboration.
Aug 10


OpenAI pauses some Astra activities over Critical Cybersecurity Risks
OpenAI restricted some Astra activities after preliminary evaluations could not rule out Critical cybersecurity capabilities, including zero-day exploitation.
Aug 10


Demystifying IDS and IPS: A powerful security shield for enterprise networks
Two familiar yet crucial defensive tools that every organization must thoroughly understand are IDS (Intrusion Detection System) and IPS (Intrusion Prevention System).
Aug 7


Vulnerability in Cursor, VS Code, and Antigravity could steal API keys
A flaw in Cursor, VS Code, and Antigravity could execute commands after one click, putting API keys, source code, and developer devices at risk.
Aug 7


Meta AI model accidentally infiltrates external system due to testing configuration error
During a recent information security assessment, an artificial intelligence (AI) model from Meta unexpectedly gained access to the internet and infiltrated the computer system of a third-party service.
Aug 6


SMOKE#SCREEN Campaign: Impersonating Zoom and Adobe updates to hijack computers
Information security researchers have recently discovered a dangerous cyberattack campaign named SMOKE#SCREEN. By spreading fake software update notifications from familiar applications like Zoom or Adobe, attackers can silently install remote control tools and gain full control over victims' computers.
Aug 6


Warning: New attack technique enables malware to hijack Google Passkey authentication keys
Cybersecurity experts have recently uncovered a new attack technique called "Pass-ta-key," which enables malware to compromise and hijack accounts even when secured by Passkeys.
Aug 6


Vietnam Cybersecurity Day, August 6: Every individual needs to build a "digital shield"
In the era of digital transformation, maintaining a safe and reliable cyberspace has become a key factor for overall development. The Vietnam Cybersecurity Day event held annually on August 6 is an important occasion to promote public awareness and responsibility regarding information security protection.
Aug 6


Google Password Manager attacks could hijack passkey-protected accounts
Unit 42 disclosed three techniques that could let malware hijack passkey-protected accounts on Chrome for Windows after a device is compromised.
Aug 6


Enterprise checklist: Preparing for a Penetration Test
To prepare for a Penetration Test, the internal IT team must provide an inventory of network assets (IPs, Domains, APIs), infrastructure diagrams, technical documentation, and necessary system access privileges.
Aug 5


Shai-Hulud worm returns to npm, infecting 868 packages with over 2 billion monthly downloads
The npm open-source ecosystem has just experienced a major shock. On August 4, 2026, a malware campaign named Shai-Hulud re-emerged as a worm (a type of malware capable of self-replicating and spreading automatically). The attack directly targeted the software supply chain, hijacking critical developer accounts and rapidly poisoning a wide array of popular programming libraries.
Aug 5
bottom of page
