The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.

A sophisticated threat actor, believed to be linked to China, has successfully infiltrated the computer systems of at least ten organizations across Southeast Asia. The attacks, which also targeted two state-owned enterprises within the region, resulted in the deployment of a previously unknown backdoor.
The attackers demonstrated a high level of technical skill and operational security, making their activities difficult to detect. While the full scope of the compromise is still under investigation, the initial findings indicate a significant breach of critical infrastructure and sensitive data within the affected nations.
The newly identified backdoor, dubbed "PortDoor" by researchers, is a custom-built piece of malware designed to provide persistent access to compromised networks. Its capabilities include remote command execution, data exfiltration, and the ability to download and install additional malicious tools. This suggests a long-term espionage or sabotage objective rather than a quick smash-and-grab operation.
The specific industries targeted have not been disclosed, but the involvement of state-owned entities points towards a strategic interest in government operations, critical infrastructure, or sensitive economic data. The geographic focus on Southeast Asia also suggests a geopolitical motivation behind the campaign.
While the attribution to a China-linked group is based on technical indicators and observed tactics, techniques, and procedures (TTPs), further analysis is ongoing to solidify the connection. Such attribution is often challenging and relies on piecing together various clues, including infrastructure overlap, code similarities, and the strategic interests of nation-states.
The discovery of this campaign highlights the persistent threat posed by advanced persistent threat (APT) groups to regional stability and national security. The use of a novel backdoor underscores the continuous evolution of cyber warfare capabilities and the need for robust defenses.
Organizations in Southeast Asia, particularly those in critical sectors and government-related entities, are advised to review their network security posture. This includes implementing strong access controls, regularly patching systems, monitoring network traffic for suspicious activity, and ensuring that endpoint detection and response (EDR) solutions are up-to-date and properly configured.
The researchers who uncovered this activity are continuing to analyze the malware and the broader campaign to understand its full impact and identify any further malicious infrastructure or targets. The findings are expected to be shared with relevant cybersecurity agencies and international partners to facilitate a coordinated response.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a