Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs.

An online education system used by South Korea's diplomatic academy was compromised by unidentified hackers for nine months, leading to the theft of personal information belonging to current and former employees of the Ministry of Foreign Affairs (MoFA). The breach of the Korea National Diplomatic Academy's e-learning platform occurred between April 2025 and February 2026.
The MoFA confirmed the incident after a government authority notified the ministry of abnormal access to the system. Following the notification, the ministry immediately shut down the affected system, which has not been restored since.
Compromised data is believed to include trainee IDs, names, email addresses, and encrypted passwords. However, the ministry stated that sensitive information such as contact details and personal photos were not affected.
Reports indicate that the attackers exploited a previously unknown zero-day vulnerability in the server software. This was reportedly compounded by misconfigured security settings, which facilitated access to the network. The ministry noted that no security update was available at the time, limiting their ability to respond.
The Korea National Diplomatic Academy provides training for diplomatic service candidates, serving diplomats preparing for overseas postings, and senior officials from various central and local government bodies. The wide range of users has raised concerns among lawmakers and security analysts regarding the potential scope of the data exposure.
The ministry has not yet determined precisely what information was accessed or exfiltrated during the nine-month compromise period. It expressed serious concern about the increasing sophistication and expanding scope of cyberattacks and stated its commitment to strengthening internal security systems in cooperation with relevant authorities.
The MoFA did not attribute the attack to any specific threat actor. In recent years, South Korea has attributed the majority of cyberattacks on its public institutions to North Korea, with the National Intelligence Service previously estimating that North Korean actors are responsible for approximately 80% of attacks targeting the South Korean government sector.
This incident is the latest in a series of high-profile data breaches that have increased pressure on Seoul to reform its approach to digital security. In June, South Korea's data protection regulator imposed a record fine of $409 million on e-commerce giant Coupang following a 2025 incident that exposed roughly 33.7 million customer accounts.
These incidents have contributed to a significant rewrite of South Korea’s Personal Information Protection Act, which is scheduled to take effect in September. The amended law will allow companies to face fines of up to 10% of their turnover for data breaches and explicitly designates the CEO as ultimately responsible for data protection compliance.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed