top of page
Cyber Security Hub
Stay updated with the latest news on technology, cybersecurity, market reports
Featured News


Cybersecurity News Roundup (20.7 - 26.7): AI-powered attacks, data breaches and critical vulnerabilities
Stay updated with the latest cybersecurity news from Vietnam and around the world, including AI-powered attacks, data breaches, critical vulnerabilities, and emerging cyber threats affecting businesses.
Jul 27


Cybersecurity landscape in Vietnam – Q2/2026: Key risks and recommendations for businesses
An analysis of Vietnam’s cybersecurity landscape in Q2 2026, covering online fraud, data breaches, malware, AI-powered threats, and key recommendations for businesses.
Jul 23


Last week in cybersecurity (June 22–28): EVN scams alert, AI manipulation, and Linux root-exploiting vulnerability
Explore last week in cybersecurity (June 22–28): EVN warns of fake OTPs, AI agents tricked into executing malware, and the DirtyClone Root flaw. Read now!
Jun 29


Optimizing IT risk management with in-depth Information Security GRC solutions
Information security GRC is increasingly becoming a critical part of IT governance strategy, helping align governance, risk, and compliance requirements into a unified model.
17 hours ago


Network maintenance for Startups: In-house or Outsourced?
Learn what a startup network maintenance solution should include, how to choose the right support model, and what to look for in a service provider.
Jul 25


Financial sector cybersecurity 2026: Decoding 6 cyberattack trends and proactive defense strategies
Decode 6 financial sector cybersecurity trends in 2026 from Darktrace & Visa. Discover how to combat ransomware and phishing with a 24/7 SOC platform from IPSIP experts!
Jul 7


Over 92,000 malware detections impersonated ChatGPT and other AI services in early 2026
Kaspersky recorded over 92,000 malware and PUA detections disguised as ChatGPT, Claude and Gemini in early 2026, highlighting growing AI impersonation risks.
20 hours ago


Alarm: AI behind nearly half of cyberattacks in Vietnam
In the first half of 2026, Vietnam's information security landscape recorded a concerning shift as artificial intelligence (AI) began directly participating in intrusion and data theft activities.
2 days ago


From Deepfakes to WhatsApp: inside a $187 million investment fraud network
GoldBull and CoinLure use deepfakes, WhatsApp and fake investment platforms in a fraud ecosystem estimated at over $187 million.
2 days ago
24H movement


Decree 333/2026/ND-CP takes effect: what businesses need to know about cybersecurity compliance
Decree 333/2026/ND-CP took effect on August 19, 2026, introducing requirements on account verification, information disclosure, content handling and system log retention.
19 hours ago


Critical GitLab vulnerability actively exploited: Severe risk to the supply chain
Just days after being publicly disclosed, a critical security vulnerability in the GitLab platform has rapidly been targeted by attackers.
20 hours ago


Over 92,000 malware detections impersonated ChatGPT and other AI services in early 2026
Kaspersky recorded over 92,000 malware and PUA detections disguised as ChatGPT, Claude and Gemini in early 2026, highlighting growing AI impersonation risks.
20 hours ago
All posts


Claude code, Gemini CLI and Codex vulnerabilities expose new CI/CD security risks
Security flaws affecting Claude Code, Gemini CLI and Codex show how AI coding agents can expose CI/CD pipelines, source code, credentials and enterprise systems.
Aug 14


Picus Blue Report 2026: Multi-million dollar defenses still miss quiet attacks
According to the annual Blue Report 2026 recently published by Picus Labs, the cybersecurity defense capabilities of enterprises are showing signs of recovery, but the truth behind these positive numbers hides many concerning vulnerabilities.
Aug 13


A vulnerability in LiteLLM drags 2,500 organizations into danger
Beginning with a vulnerability in an auxiliary tool, the supply chain attack targeting LiteLLM rapidly expanded, threatening numerous technology systems worldwide.
Aug 13


Cybersecurity risks when businesses rely solely on internal IT staff
About enterprise network security. Can 1–2 internal IT staff adequately protect enterprise network security? Explore common security gaps, attack risks, and practical cybersecurity options.
Aug 13


Red Hat ACM hit by critical CVE that could lead to cluster-admin access
CVE-2026-10090 in Red Hat ACM scores 9.9 CVSS and may allow users with edit permissions to escalate to cluster-admin. Enterprises should review RBAC.
Aug 13


Critical Zoom vulnerability: risk of computer takeover via a familiar feature
A critical chain of security vulnerabilities has recently been discovered in Zoom, allowing anyone in a meeting – whether a presenter or an attendee – to take control of other participants' computers.
Aug 12


Wave of scans target critical VMware vCenter vulnerabilities
Cybersecurity experts have recently detected a sharp surge in scanning activity targeting VMware vCenter systems. This serves as an early warning signal that threat actors are actively hunting for unpatched targets in preparation for dangerous intrusion attempts.
Aug 12


CVE-2026-64638: WordPress XSS2Shell flaw could lead to PHP code execution
WordPress patched CVE-2026-64638, a pre-auth reflected XSS flaw that could lead to PHP code execution when an administrator interacts with attacker-controlled content.
Aug 12


Risk of enterprise data leakage from "one-click" vulnerability on Atlassian Rovo AI
The discovery of RovoBlast - a severe security vulnerability in the Atlassian Rovo AI assistant serves as proof that an enterprise's internal data can be exfiltrated through a single malicious link.
Aug 11


Levi Strauss data breach: 3 employee computers accessed via social engineering
Levi Strauss & Co. said it identified a cybersecurity incident in which an unauthorized third party used social engineering to gain access to three company-issued employee computers. From those devices, certain corporate information was accessed and exfiltrated.
Aug 11


What to do when Metabase faces a critical Zero-Day vulnerability?
Metabase has confirmed a critical cybersecurity incident involving an actively exploited zero-day vulnerability.
Aug 10


The hybrid model: Combining IT outsourcing with outsourced SOC services
Learn how combining IT outsourcing and cybersecurity with an outsourced SOC helps enterprises define responsibilities and improve IT–SOC collaboration.
Aug 10


OpenAI pauses some Astra activities over Critical Cybersecurity Risks
OpenAI restricted some Astra activities after preliminary evaluations could not rule out Critical cybersecurity capabilities, including zero-day exploitation.
Aug 10


Demystifying IDS and IPS: A powerful security shield for enterprise networks
Two familiar yet crucial defensive tools that every organization must thoroughly understand are IDS (Intrusion Detection System) and IPS (Intrusion Prevention System).
Aug 7


Vulnerability in Cursor, VS Code, and Antigravity could steal API keys
A flaw in Cursor, VS Code, and Antigravity could execute commands after one click, putting API keys, source code, and developer devices at risk.
Aug 7


Meta AI model accidentally infiltrates external system due to testing configuration error
During a recent information security assessment, an artificial intelligence (AI) model from Meta unexpectedly gained access to the internet and infiltrated the computer system of a third-party service.
Aug 6


SMOKE#SCREEN Campaign: Impersonating Zoom and Adobe updates to hijack computers
Information security researchers have recently discovered a dangerous cyberattack campaign named SMOKE#SCREEN. By spreading fake software update notifications from familiar applications like Zoom or Adobe, attackers can silently install remote control tools and gain full control over victims' computers.
Aug 6


Vietnam Cybersecurity Day, August 6: Every individual needs to build a "digital shield"
In the era of digital transformation, maintaining a safe and reliable cyberspace has become a key factor for overall development. The Vietnam Cybersecurity Day event held annually on August 6 is an important occasion to promote public awareness and responsibility regarding information security protection.
Aug 6


Google Password Manager attacks could hijack passkey-protected accounts
Unit 42 disclosed three techniques that could let malware hijack passkey-protected accounts on Chrome for Windows after a device is compromised.
Aug 6


Shai-Hulud worm returns to npm, infecting 868 packages with over 2 billion monthly downloads
The npm open-source ecosystem has just experienced a major shock. On August 4, 2026, a malware campaign named Shai-Hulud re-emerged as a worm (a type of malware capable of self-replicating and spreading automatically). The attack directly targeted the software supply chain, hijacking critical developer accounts and rapidly poisoning a wide array of popular programming libraries.
Aug 5
bottom of page
