Cybersecurity Weekly News (September 7–13): Scam Warnings, Tighter Data Protection and AI Agent Attacks
Cybersecurity developments during September 7–13, 2026 highlighted several notable trends in Vietnam, from back-to-school scams and stricter data protection responsibilities to the growing use of AI in securing digital infrastructure. Internationally, active vulnerability exploitation and the use of AI Agents to automate offensive operations continued to reduce the time available for defenders to respond.
Key developments included warnings about school impersonation and “online kidnapping” scams, new data governance requirements for Vietnamese businesses, the exposure of an APIS database containing more than 220 million passenger records, active exploitation of Cisco Secure Firewall Management Center and a campaign that reportedly used hundreds of AI Agents to target PaperCut NG/MF systems.
Businesses can follow additional developments through the IPSIP cybersecurity news section.
I. Cybersecurity News in Vietnam
1. Back-to-school scams use school impersonation and “online kidnapping” scenarios
The start of the school year has created new opportunities for cybercriminals to exploit the urgency and concerns of parents, students and educational communities.
A warning published on the Vietnamese Ministry of Public Security’s portal on September 7, 2026 described scenarios in which attackers collect information from social media or class groups, then impersonate teachers, school administrators or accounting staff to request tuition payments, textbook fees, uniform payments or transfers to attacker-controlled bank accounts.
A more serious variation involves so-called “online kidnapping” schemes. Attackers impersonate law enforcement officers, accuse students of being involved in criminal investigations and instruct them to keep the situation secret, cut off contact with their families and isolate themselves. Once psychological control is established, the attackers pressure relatives into transferring money.
Recommended action: Businesses should establish out-of-band verification procedures for unusual financial requests and require confirmation through at least one independent channel before transferring funds or changing payment details. Employees should also receive recurring training on phishing, social engineering, identity impersonation and suspicious activity reporting. IPSIP provides practical guidance in its article on cybersecurity awareness training for employees.
The risk is not limited to individuals. Businesses may face similar fraud attempts in which criminals impersonate customers, suppliers or executives to request payments, change bank account details or obtain sensitive information.
2. Corporate cybersecurity and data protection responsibilities continue to expand
Vietnam’s Law on Personal Data Protection No. 91/2025/QH15 took effect on January 1, 2026, while the Cybersecurity Law No. 116/2025/QH15 became effective on July 1, 2026.
The evolving legal framework moves cybersecurity and data protection beyond purely technical responsibilities and places them within broader corporate governance.
Businesses cannot simply transfer all responsibility to cloud providers, SaaS vendors, call centers, marketing partners or IT service providers. Relationships between data controllers, data processors and third parties need to be clearly defined and supported by appropriate technical and organizational safeguards.

Recommended action: Businesses should map the personal data they collect and process, identify where it is stored, define who can access it and document which third parties are involved. Least Privilege, MFA, logging, data classification and periodic vendor assessments should be part of the governance process. Additional context is available in IPSIP’s overview of the 2026 Personal Data Protection Law.
3. Decree 314/2026/ND-CP brings data security into the emerging data marketplace
Vietnamese Decree 314/2026/ND-CP, issued on August 8, 2026 and scheduled to take effect on September 25, 2026, regulates the operation of data exchanges in Vietnam.
The regulation establishes principles covering data listing, transactions, valuation and exploitation. Importantly, activities on data exchanges must comply with cybersecurity, data security and personal data protection requirements.
Recommended action: Before data is shared, traded or reused, businesses should verify its origin, ownership or processing rights, sensitivity level and intended purpose. Encryption at rest and in transit, key management, access control and Data Loss Prevention can help reduce the risk of unauthorized access or transfer. IPSIP provides further guidance in its article on enterprise data encryption.
4. AI gains attention in digital infrastructure management and government cybersecurity
Another trend highlighted during the week was the growing use of artificial intelligence in digital infrastructure management and cybersecurity for Vietnam’s digital government.
AI can support traffic analysis, resource forecasting, abnormal behavior detection and faster alert processing. Its primary value does not lie in replacing existing security tools, but in processing large volumes of telemetry and helping identify behavioral patterns that static rules may fail to detect.
This can support a shift from primarily reactive security toward earlier detection and more proactive defense.
Recommended action: Organizations deploying AI in security operations should control both what data AI systems can access and how much trust is placed in automated decisions. AI Governance, data classification, model access controls, activity logging and human-in-the-loop review should be designed from the start. IPSIP provides additional context in Cybersecurity in the AI era: Risks and defensive strategies.
👉 Artificial intelligence in digital infrastructure and cybersecurity for Vietnam’s digital government
5. More than 220 million passenger records exposed through an APIS-related system
On September 8, 2026, an Advance Passenger Information System-related database containing more than 220 million passenger and crew records was found to be accessible online through a chain of security misconfigurations.
The exposed information reportedly included names, passport numbers and flight details. According to researchers cited in reporting on the incident, the system appeared to have links to an organization in Vietnam. At the time of publication, however, available information was not sufficient to formally attribute responsibility to a specific Vietnamese organization.
Recommended action: Businesses should review databases, storage buckets, APIs, administrative interfaces and other services exposed to the Internet. Unnecessary public access should be removed, while deny-by-default policies should be applied to sensitive data. Cloud Security Posture Management, IAM, logging and regular configuration reviews are particularly important for systems handling large data volumes. IPSIP provides a practical guide on detecting and fixing cloud security misconfigurations.
II. International Cybersecurity News
6. Cisco Secure FMC actively exploited through critical CVE-2026-20079
On September 9, 2026, Cisco updated its advisory for CVE-2026-20079 affecting Cisco Secure Firewall Management Center Software and confirmed active exploitation.
The vulnerability received a CVSS score of 10.0, and Cisco stated that no workaround was available as an alternative to applying the required update.

CVE-2026-20079 affects the web interface of Secure FMC. An unauthenticated remote attacker can send specially crafted HTTP requests to bypass authentication and gain highly privileged access to the affected system.
Recommended action: Organizations using Cisco Secure FMC should identify affected versions, apply vendor patches as a priority and review logs for suspicious activity that may have occurred before the update was installed. Firewalls, VPNs and Internet-facing management interfaces should also be included in regular vulnerability assessment cycles. IPSIP outlines this approach in its guide to information security vulnerability assessment.
7. BlueMoon chains Chrome and Windows zero-days in cyber-espionage operations
Proofpoint disclosed the BlueMoon exploit kit on September 9, 2026. The toolkit was reportedly used by multiple espionage groups to combine Chromium browser vulnerabilities with a Windows privilege escalation flaw.
The exploit chain included CVE-2026-85046, CVE-2026-87491 and CVE-2026-85880. After exploiting the browser and escaping the sandbox, attackers could use the Windows flaw to elevate privileges and deploy additional payloads.
Recommended action: Browsers, operating systems, endpoint security products and third-party applications should be managed under a unified, risk-based patching process. Vulnerabilities with evidence of active exploitation, Remote Code Execution or Privilege Escalation should be prioritized over issues that have high CVSS scores but no evidence of exploitation. IPSIP discusses this model in why businesses need to change how they manage security patches rh2 fu2 .
8.Hundreds of AI Agents reportedly used to attack 395 organizations through PaperCut
One of the most notable developments of the week came from a GreyNoise report published on September 9, 2026.
According to GreyNoise, a threat actor assessed as likely Russian-speaking used hundreds of AI Agents to develop, test and deploy exploits against PaperCut NG/MF.
The campaign targeted CVE-2026-81578 and CVE-2026-82078. GreyNoise reported that at least 440 PaperCut instances across 395 organizations in 48 countries were compromised. Credentials were collected from 280 victims, operating system or domain secrets were obtained from 147 environments, and administrative access was achieved at 12 organizations.
Recommended action: Businesses should assume that the time between vulnerability disclosure and exploitation will continue to decrease. Internet-facing syste ureb23u ms should be continuously monitored and protected through a combination of Vulnerability Management, EDR/XDR, SIEM and a defined Incident Response process. When compromise is suspected, organizations should isolate affected systems, preserve logs, revoke potentially exposed credentials and activate an investigation workflow. IPSIP provides further guidance in its Incident Response Guide for businesses.
III. What Should Businesses Prioritize After September 7–13?
The week’s developments show that cybersecurity risk is not concentrated in one technology or attack type.
Social engineering continues to exploit human behavior. Misconfigurations can expose large volumes of sensitive data. Internet-facing security devices can become entry points into enterprise networks. At the same time, AI is accelerating attack techniques that already existed.

Organizations without continuous monitoring capabilities may consider IPSIP SOC 24/7 to centralize detection and alert handling. Businesses that need to identify weaknesses across their attack surface can use vulnerability scanning and assessment.
For critical or Internet-facing systems, Penetration Testing can provide deeper insight into whether individual weaknesses can be combined into practical attack paths.
For Vietnamese businesses, the immediate priority is not necessarily to deploy more security tools. Organizations first need to understand which assets are exposed, which data requires protection, which vulnerabilities must be fixed first and who is responsible when an incident occurs.
References
Government News – Full text of Decree 314/2026/ND-CP regulating data exchange operations
BleepingComputer – Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
BleepingComputer – New BlueMoon kit exploited Windows and Chrome zero-day flaws











Comments