top of page
Cyber Security Hub
Stay updated with the latest news on technology, cybersecurity, market reports
Featured News


Cybersecurity News Roundup (20.7 - 26.7): AI-powered attacks, data breaches and critical vulnerabilities
Stay updated with the latest cybersecurity news from Vietnam and around the world, including AI-powered attacks, data breaches, critical vulnerabilities, and emerging cyber threats affecting businesses.
6 days ago


Cybersecurity landscape in Vietnam – Q2/2026: Key risks and recommendations for businesses
An analysis of Vietnam’s cybersecurity landscape in Q2 2026, covering online fraud, data breaches, malware, AI-powered threats, and key recommendations for businesses.
Jul 23


Last week in cybersecurity (June 22–28): EVN scams alert, AI manipulation, and Linux root-exploiting vulnerability
Explore last week in cybersecurity (June 22–28): EVN warns of fake OTPs, AI agents tricked into executing malware, and the DirtyClone Root flaw. Read now!
Jun 29


Network maintenance for Startups: In-house or Outsourced?
Learn what a startup network maintenance solution should include, how to choose the right support model, and what to look for in a service provider.
Jul 25


Financial sector cybersecurity 2026: Decoding 6 cyberattack trends and proactive defense strategies
Decode 6 financial sector cybersecurity trends in 2026 from Darktrace & Visa. Discover how to combat ransomware and phishing with a 24/7 SOC platform from IPSIP experts!
Jul 7


IPSIP Vietnam Pentest services: Penetration Testing for businesses
IPSIP provides pentest services in Vietnam for websites, APIs, mobile applications, networks, and cloud environments, including reports, remediation consulting, and retesting.
Jul 2


Prompt Injection: Hackers hide malicious instructions to manipulate enterprise AI
This technique is known as indirect prompt injection. Malicious instructions can be placed in the email body, subject line, quoted email threads, attachments, or hidden formatting code.
2 days ago


OpenAI's AI Agent breaches boundaries to infiltrate second company: A new cybersecurity concern
The incident involving OpenAI's AI agent – AI systems capable of operating autonomously and performing tasks independently – freely operating out of control is becoming the center of attention in the information security community. The latest developments show that the incident is no longer limited to the breach of the Hugging Face platform, but has expanded to a second technology company based in New York, Modal Labs.
4 days ago


570 vulnerabilities are just the beginning: Businesses need to change how they manage security patches
Beyond the increasing number of vulnerabilities, the speed of flaw detection and patch release is accelerating thanks to artificial intelligence (AI). This forces organizations to re-evaluate security update processes that have been maintained for years.
Jul 22
24H movement


CosmosEscape flaw threatens the Azure Cosmos DB platform
CosmosEscape – a critical security vulnerability in Microsoft's Azure Cosmos DB database service allows attackers to bypass authorization barriers, conduct cross-tenant interactions between user accounts, and threaten data security on a global scale.
2 days ago


Russian threat group exploits Microsoft OWA vulnerability: The emergence of sophisticated malware OWAReaper
A dangerous cyber attack campaign targeting Microsoft Outlook Web Access (OWA) systems has recently been discovered, directly threatening government agencies in the US and Europe.
2 days ago


Prompt Injection: Hackers hide malicious instructions to manipulate enterprise AI
This technique is known as indirect prompt injection. Malicious instructions can be placed in the email body, subject line, quoted email threads, attachments, or hidden formatting code.
2 days ago
All posts


Prompt Injection: Hackers hide malicious instructions to manipulate enterprise AI
This technique is known as indirect prompt injection. Malicious instructions can be placed in the email body, subject line, quoted email threads, attachments, or hidden formatting code.
2 days ago


OpenAI's AI Agent breaches boundaries to infiltrate second company: A new cybersecurity concern
The incident involving OpenAI's AI agent – AI systems capable of operating autonomously and performing tasks independently – freely operating out of control is becoming the center of attention in the information security community. The latest developments show that the incident is no longer limited to the breach of the Hugging Face platform, but has expanded to a second technology company based in New York, Modal Labs.
4 days ago


More than 70 fake windows app websites caught distributing malware
Researchers have uncovered more than 70 fake Windows application websites distributing malware, highlighting the growing threat of SEO poisoning and unofficial software downloads.
4 days ago


OpenAI AI model bypasses testing guardrails, executes unprecedented cyberattack on Hugging Face
A rare cybersecurity incident recently occurred in the tech industry when an artificial intelligence (AI) system developed by OpenAI autonomously escaped its testing environment, connected to the internet, and carried out an intrusion into the servers of Hugging Face - a platform hosting open-source AI models and datasets.
Jul 23


The first AI-driven ransomware campaign: The power of technology and the true role of humans
The cybersecurity community recently witnessed a remarkable turning point as artificial intelligence (AI) executed a cyberattack entirely on its own.
Jul 9


FortiBleed identified as the initial access vector for INC and Lynx ransomware operations
A new report from SOCRadar confirms that the FortiBleed campaign has resulted in 409 compromised FortiGate administrator accounts, 354 successful intrusions, and at least 12 confirmed ransomware incidents. This marks the first time technical evidence has directly linked FortiBleed to the ransomware operations of the INC and Lynx groups.
Jul 7


Warning on the threats of Shadow AI: a new attack technique targeting AI coding assistants
Instead of planting malware directly, the attacker cleverly inserts hidden instructions to trick autonomous AI assistants like Claude Code into automatically triggering remote destructive commands. This vulnerability is the clearest evidence of the dangers of Shadow AI.
Jul 2


Google patches 28 dangerous vulnerabilities in Chrome
Google has officially rolled out a major security update for Chrome, addressing 28 vulnerabilities. Among these are several critical flaws that could allow attackers to execute malicious code on targeted systems.
Jun 17


Meta acknowledges AI chatbot flaw that led to thousands of Instagram accounts being hacked
A serious security incident was recently confirmed by Meta, where an artificial intelligence (AI) support tool was exploited by cybercriminals, putting thousands of Instagram user accounts at risk of data exposure and unauthorized access.
Jun 15


Experiencing the unique cybersecurity space in Ho Chi Minh city
This meaningful activity took place continuously for three days, from June 11 to June 13, 2026, at Nguyen Hue walking street, Ho Chi Minh city. It was a special zone within the framework of the "Peaceful Fatherland" Gala art program organized by the Ministry of Public Security.
Jun 15


Global outage hits Facebook, Instagram: a technical infrastructure perspective
On the night of June 12, millions of users worldwide suddenly lost access to familiar applications within the Meta ecosystem. This widespread disruption not only caused inconvenience to individual users but also led to a drop of nearly $1 billion in billionaire Mark Zuckerberg's net worth.
Jun 13


GitHub changes npm security rules to block supply-chain attacks
To address these vulnerabilities, GitHub has announced significant security-focused modifications arriving with the upcoming npm v12 next month
Jun 12


Operation TaxShadow campaign distributes invisible malware via fake tax emails
A newly discovered campaign named Operation TaxShadow has been observed leveraging phishing emails impersonating tax authorities to trick Windows users into downloading dangerous malware. Remarkably, this malware operates entirely within the system memory, leaving minimal digital footprints and making detection and prevention extremely difficult.
Jun 11


Critical Check Point VPN flaw exploited to bypass user passwords
A severe security vulnerability is being actively exploited by cybercriminals to infiltrate corporate networks without requiring valid user passwords.
Jun 10


Google chrome issues urgent update patching over 400 security vulnerabilities
Google has rolled out one of its largest security patch bundles ever for the Chrome browser. Users worldwide, from individuals to large enterprises, are strongly advised to update immediately to defend their systems against a wide array of cyber threats.
Jun 9


Cybercriminals kick off ahead Of World Cup 2026: what fans and businesses need to know
Hackers are using fake ticket websites, malicious livestreams, impersonation accounts, and scam applications to exploit the passion of global fans and gaps in corporate security.
Jun 9


Warning: hackers exploit SolarWinds Serv-U flaw to cause server crashes
CISA has issued an urgent warning regarding a newly patched, high-severity vulnerability within SolarWinds Serv-U. Cybercriminals are actively exploiting this flaw in the wild, with the primary intent of crashing enterprise servers.
Jun 8


AI boom exploited: how the "ClickFix" campaign stealthily steals data via trusted platforms
Instead of relying on traditional file downloads, these attackers exploit user trust in established platforms to silently exfiltrate highly sensitive data directly from target devices.
Jun 5


Operation "Miasma": Red Hat cloud services hit by mass account-stealing cyberattack
A massive supply chain cyberattack has recently been uncovered, turning trusted open-source code libraries into active tools of espionage. Named "Miasma: The Spreading Blight," this dangerous campaign directly endangers development environments and cloud infrastructure through official package releases from Red Hat.
Jun 3


CISA urges immediate audits following waves of attacks on software development pipelines
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to security teams worldwide, highlighting a recent wave of cyberattacks targeting software development pipelines...
Jun 1
bottom of page
