South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]

South Korea's Ministry of Foreign Affairs (MFA) has confirmed a data breach affecting the National Diplomatic Academy's online education system, leading to the exposure of personal information belonging to current and former employees, including diplomats stationed abroad. The breach, which occurred between April 2025 and February 2026, was attributed to an unknown threat actor exploiting a vulnerability in the Academy's server.
The MFA stated that approximately 6,000 individuals were impacted, with 350 of them being current government attachés serving overseas. However, some reports from Korean media suggest the number of affected individuals could be as high as 10,000. The compromised data includes IDs, names, email addresses, and encrypted passwords of those enrolled in the education system. Official job titles and departmental affiliations were also reportedly exposed.
The MFA clarified that no unique identification numbers, sensitive information, mobile phone numbers, photographs, or home addresses were compromised in the incident. The online education platform, established in 2022 to facilitate remote training during the COVID-19 pandemic, has since been utilized for government personnel training and video conferencing.
The breach remained undetected for ten months, from April 2025 until February 2026, when it was discovered by South Korea's National Intelligence Service, which subsequently alerted the MFA. Reports indicate that the compromised server was located within the MFA's headquarters and was not subjected to regular security scrutiny, which may have contributed to the prolonged undetected access.
The Ministry delayed public disclosure of the incident for five months, making the announcement in July 2026. An MFA spokesperson, Park Il, explained that the delay was due to the sensitive nature of the matter concerning diplomatic and security affairs, requiring thorough review and analysis before public release.
Following the discovery, the MFA has blocked access to the online education system and implemented additional security measures. Potentially affected individuals have been advised to remain vigilant for suspicious communications and to report any such instances to the ministry's security department. The MFA specifically cautioned against emails from unclear or unknown sources.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.