top of page
Cyber Security Hub
Stay updated with the latest news on technology, cybersecurity, market reports
Featured News


Cybersecurity News Roundup (20.7 - 26.7): AI-powered attacks, data breaches and critical vulnerabilities
Stay updated with the latest cybersecurity news from Vietnam and around the world, including AI-powered attacks, data breaches, critical vulnerabilities, and emerging cyber threats affecting businesses.
Jul 27


Cybersecurity landscape in Vietnam – Q2/2026: Key risks and recommendations for businesses
An analysis of Vietnam’s cybersecurity landscape in Q2 2026, covering online fraud, data breaches, malware, AI-powered threats, and key recommendations for businesses.
Jul 23


Last week in cybersecurity (June 22–28): EVN scams alert, AI manipulation, and Linux root-exploiting vulnerability
Explore last week in cybersecurity (June 22–28): EVN warns of fake OTPs, AI agents tricked into executing malware, and the DirtyClone Root flaw. Read now!
Jun 29


Network maintenance for Startups: In-house or Outsourced?
Learn what a startup network maintenance solution should include, how to choose the right support model, and what to look for in a service provider.
Jul 25


Financial sector cybersecurity 2026: Decoding 6 cyberattack trends and proactive defense strategies
Decode 6 financial sector cybersecurity trends in 2026 from Darktrace & Visa. Discover how to combat ransomware and phishing with a 24/7 SOC platform from IPSIP experts!
Jul 7


IPSIP Vietnam Pentest services: Penetration Testing for businesses
IPSIP provides pentest services in Vietnam for websites, APIs, mobile applications, networks, and cloud environments, including reports, remediation consulting, and retesting.
Jul 2


Claude code, Gemini CLI and Codex vulnerabilities expose new CI/CD security risks
Security flaws affecting Claude Code, Gemini CLI and Codex show how AI coding agents can expose CI/CD pipelines, source code, credentials and enterprise systems.
23 hours ago


Critical Zoom vulnerability: risk of computer takeover via a familiar feature
A critical chain of security vulnerabilities has recently been discovered in Zoom, allowing anyone in a meeting – whether a presenter or an attendee – to take control of other participants' computers.
3 days ago


OpenAI pauses some Astra activities over Critical Cybersecurity Risks
OpenAI restricted some Astra activities after preliminary evaluations could not rule out Critical cybersecurity capabilities, including zero-day exploitation.
5 days ago
24H movement


GitLab releases emergency patch for 13 security vulnerabilities: What you need to know
Source code management platform GitLab has officially released new security updates to address 13 vulnerabilities across its system.
20 hours ago


Hackers mass attack Microsoft SharePoint servers after public PoC release
Shortly after proof-of-concept (PoC) tools were widely shared online, hacker groups quickly leveraged them to launch real-world attacks against Microsoft SharePoint servers.
21 hours ago


Claude code, Gemini CLI and Codex vulnerabilities expose new CI/CD security risks
Security flaws affecting Claude Code, Gemini CLI and Codex show how AI coding agents can expose CI/CD pipelines, source code, credentials and enterprise systems.
23 hours ago
All posts


Hackers mass attack Microsoft SharePoint servers after public PoC release
Shortly after proof-of-concept (PoC) tools were widely shared online, hacker groups quickly leveraged them to launch real-world attacks against Microsoft SharePoint servers.
21 hours ago


Claude code, Gemini CLI and Codex vulnerabilities expose new CI/CD security risks
Security flaws affecting Claude Code, Gemini CLI and Codex show how AI coding agents can expose CI/CD pipelines, source code, credentials and enterprise systems.
23 hours ago


Picus Blue Report 2026: Multi-million dollar defenses still miss quiet attacks
According to the annual Blue Report 2026 recently published by Picus Labs, the cybersecurity defense capabilities of enterprises are showing signs of recovery, but the truth behind these positive numbers hides many concerning vulnerabilities.
2 days ago


A vulnerability in LiteLLM drags 2,500 organizations into danger
Beginning with a vulnerability in an auxiliary tool, the supply chain attack targeting LiteLLM rapidly expanded, threatening numerous technology systems worldwide.
2 days ago


Cybersecurity risks when businesses rely solely on internal IT staff
About enterprise network security. Can 1–2 internal IT staff adequately protect enterprise network security? Explore common security gaps, attack risks, and practical cybersecurity options.
2 days ago


Red Hat ACM hit by critical CVE that could lead to cluster-admin access
CVE-2026-10090 in Red Hat ACM scores 9.9 CVSS and may allow users with edit permissions to escalate to cluster-admin. Enterprises should review RBAC.
2 days ago


Critical Zoom vulnerability: risk of computer takeover via a familiar feature
A critical chain of security vulnerabilities has recently been discovered in Zoom, allowing anyone in a meeting – whether a presenter or an attendee – to take control of other participants' computers.
3 days ago


Wave of scans target critical VMware vCenter vulnerabilities
Cybersecurity experts have recently detected a sharp surge in scanning activity targeting VMware vCenter systems. This serves as an early warning signal that threat actors are actively hunting for unpatched targets in preparation for dangerous intrusion attempts.
3 days ago


CVE-2026-64638: WordPress XSS2Shell flaw could lead to PHP code execution
WordPress patched CVE-2026-64638, a pre-auth reflected XSS flaw that could lead to PHP code execution when an administrator interacts with attacker-controlled content.
3 days ago


Risk of enterprise data leakage from "one-click" vulnerability on Atlassian Rovo AI
The discovery of RovoBlast - a severe security vulnerability in the Atlassian Rovo AI assistant serves as proof that an enterprise's internal data can be exfiltrated through a single malicious link.
4 days ago


Levi Strauss data breach: 3 employee computers accessed via social engineering
Levi Strauss & Co. said it identified a cybersecurity incident in which an unauthorized third party used social engineering to gain access to three company-issued employee computers. From those devices, certain corporate information was accessed and exfiltrated.
4 days ago


What to do when Metabase faces a critical Zero-Day vulnerability?
Metabase has confirmed a critical cybersecurity incident involving an actively exploited zero-day vulnerability.
5 days ago


The hybrid model: Combining IT outsourcing with outsourced SOC services
Learn how combining IT outsourcing and cybersecurity with an outsourced SOC helps enterprises define responsibilities and improve IT–SOC collaboration.
5 days ago


OpenAI pauses some Astra activities over Critical Cybersecurity Risks
OpenAI restricted some Astra activities after preliminary evaluations could not rule out Critical cybersecurity capabilities, including zero-day exploitation.
5 days ago


Demystifying IDS and IPS: A powerful security shield for enterprise networks
Two familiar yet crucial defensive tools that every organization must thoroughly understand are IDS (Intrusion Detection System) and IPS (Intrusion Prevention System).
Aug 7


Vulnerability in Cursor, VS Code, and Antigravity could steal API keys
A flaw in Cursor, VS Code, and Antigravity could execute commands after one click, putting API keys, source code, and developer devices at risk.
Aug 7


Meta AI model accidentally infiltrates external system due to testing configuration error
During a recent information security assessment, an artificial intelligence (AI) model from Meta unexpectedly gained access to the internet and infiltrated the computer system of a third-party service.
Aug 6


SMOKE#SCREEN Campaign: Impersonating Zoom and Adobe updates to hijack computers
Information security researchers have recently discovered a dangerous cyberattack campaign named SMOKE#SCREEN. By spreading fake software update notifications from familiar applications like Zoom or Adobe, attackers can silently install remote control tools and gain full control over victims' computers.
Aug 6


Vietnam Cybersecurity Day, August 6: Every individual needs to build a "digital shield"
In the era of digital transformation, maintaining a safe and reliable cyberspace has become a key factor for overall development. The Vietnam Cybersecurity Day event held annually on August 6 is an important occasion to promote public awareness and responsibility regarding information security protection.
Aug 6


Google Password Manager attacks could hijack passkey-protected accounts
Unit 42 disclosed three techniques that could let malware hijack passkey-protected accounts on Chrome for Windows after a device is compromised.
Aug 6
bottom of page
