top of page

Last week in Cybersecurity (May, 18 - 24): High-profile breaches in Vietnam and global crackdowns on cybercrime

The digital landscape is evolving rapidly, but it brings along significant information security risks. Over the past week, the domestic and international cybersecurity scenes have seen complex developments. While Vietnam grappled with a surge in cyber espionage and critical data leaks, global law enforcement agencies actively dismantled major underground cybercrime infrastructures.

Domestic situation: Businesses and Ministries confront critical data risks

In Vietnam, information security has become more urgent than ever as threat actors continuously target both corporate networks and public sectors.

  • Surge in cyber espionage attacks: According to recent reports, Vietnamese enterprises suffered over 320,000 cyber espionage attacks (malware designed to covertly monitor and gather sensitive information). In fact, spyware attacks across Southeast Asia spiked by 18% in 2025, with Vietnam recording the highest number of corporate network attacks in the region.

Vietnam is facing a growing wave of espionage.
Vietnam is facing a growing wave of espionage.
  • Hackers Infiltrate Two Ministerial Systems: The National Cybersecurity Center (VNCERT) revealed that it responded to a highly severe data breach involving the systems of two ministries. Remarkably, even though these agencies were equipped with Security Operations Centers (SOCs), the platforms failed to log the attack. Experts note that the hackers' behavior subtly blended into normal user activities, highlighting a critical need to enhance the capabilities of dedicated security personnel.

Vietnam Security Summit 2026: Defense gaps in the AI and Quantum era

The Vietnam Security Summit 2026 (Vietnam Security Summit 2026), held in Hanoi on May 22, shed light on core vulnerabilities within the national digital defense architecture.

Vietnam Security Summit 2026
Vietnam Security Summit 2026
  • Vietnam’s "Achilles' heels": Experts pointed out that the biggest weaknesses currently lie in fragmented defense systems, a severe shortage of high-quality cybersecurity talent, and limited user awareness. Today, hackers have shifted their focus from merely stealing data to paralyzing essential services, hijacking operations, and sabotaging critical infrastructure, posing direct threats to national security and the economy.

  • The need for unified risk management: The current challenge is not a lack of security tools, but rather a lack of centralized control, leading to restricted visibility and slow incident response. Organizations must transition from passive defense to systematic risk management, combining automation with human expertise.

  • Future technological threats: The rapid advancement of quantum computing is projected to break traditional encryption models soon. Consequently, proactively boosting cybersecurity capabilities for the post-quantum era and Artificial Intelligence (AI) is a vital mission. Additionally, according to the Department of Cybersecurity and High-Tech Crime Prevention (A05), the illicit trade of personal data remains rampant on dark web forums and social media. Between 2023 and 2025, authorities prosecuted over 30 cases involving illegal data trading, affecting more than 160 million citizen records.

International spotlight: Global law enforcement crackdowns and major vulnerabilities

On the international front, global law enforcement recorded massive wins against cybercriminals, alongside critical warnings regarding human errors and zero-day exploits, as highlighted in the SentinelOne weekly report and Applied Tech updates:

  • Massive Interpol rakedown: Working with partners across 13 countries, Interpol successfully neutralized 53 servers used to distribute malware and run phishing campaigns, identifying at least 3,867 victims. The operation dismantled an investment scam ring in Jordan, a Phishing-as-a-Service platform in Algeria, and seized related equipment in Qatar, Oman, and Morocco.

  • Dismantling "First VPN" anonymity network: International law enforcement successfully took down a criminal virtual private network service called "First VPN". This tool was actively used by over 25 ransomware groups to hide their destructive tracks and data theft. Authorities seized 33 servers and shut down the network's domains.

  • Arrest of "Kimwolf" botnet mastermind: A 23-year-old individual in Canada was arrested for allegedly operating the "Kimwolf" botnet. This network hijacked nearly 2 million smart IoT devices (such as digital photo frames and webcams) to launch over 25,000 massive DDoS attacks, reaching a record traffic volume of nearly 30 Tbps, targeting organizations including the US Department of Defense.

  • CISA Cloud access keys exposed: In a surprising turn of events, a contractor for the US Cybersecurity and Infrastructure Security Agency (CISA) accidentally exposed AWS GovCloud access keys on a public GitHub repository. The leak occurred because the individual synced work files between their agency computer and a personal home computer.

  • Sophisticated malware targeting macOS users: A new variant of information-stealing malware targeting macOS was discovered. Attackers disguised the malware as familiar productivity apps from major ecosystems like Apple, Google, and Microsoft to quietly harvest clipboard data and browser credentials.

Software supply chain risks and critical system flaws

According to recent coverage by Cyber Magazine and technical briefs, sophisticated attacks are targeting core development pipelines and administrative platforms.

Supply chain risks
Supply chain risks
  • Poisoning open-source repositories: The financially motivated threat group TeamPCP executed a campaign dubbed "Mini Shai-Hulud". By exploiting a flaw in GitHub Actions, the group injected malicious code into popular packages within TanStack npm and PyPi repositories to steal cloud credential keys when developers downloaded them.

  • Financial sector target of AI-driven attacks: An Akamai report highlighted that cybercriminals are leveraging AI-controlled botnets to launch prolonged, complex DDoS attacks against financial institutions. Gaps in API controls combined with geopolitical factors keep the financial sector in the crosshairs.

  • Urgent warnings for critical vulnerabilities: * Alongside two Microsoft Defender zero-days (including CVE-2026-41091) which the US government ordered to be patched by June 3, 2026, Applied Tech's weekly brief issued alerts for a maximum-severity flaw (CVSS 10.0/10) designated CVE-2026-20223 in Cisco Secure Workload. This vulnerability allows unauthenticated attackers to gain full Site Admin privileges.

    • Concurrently, the Drupal Core content management framework issued an urgent advisory regarding an actively exploited SQL Injection vulnerability (CVE-2026-9082), which CISA recently added to its Known Exploited Vulnerabilities (KEV) catalog due to widespread scanning and attacks.

This past week paints a clear picture: the digital world has no absolute borders. From real-world lessons in Vietnamese ministries and enterprises to accidental leaks at top-tier security agencies like CISA, the only way to safeguard digital assets is through unified harmony. Organizations must shift from fragmented security to comprehensive risk management, elevate human awareness, and enforce continuous patching to preempt threats before it's too late.

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page