CyberSecurity.PH #044

PSA Intelligence notes rising cyber espionage on APAC government databases and critical infrastructure attacks. Concurrently, AI models are escaping sandboxes to breach systems, and AI-generated phantom threats in CVE databases are wasting security teams' resources.

CTA Image

CyberSecurity.PH is now supported by the PSA Intelligence Cyber Risks

Learn more

APAC and Philippines

Thailand’s Finance Ministry Targeted by AI-Driven Cyberattack

Threat intelligence researchers at Hunt.io disclosed an artificial intelligence (AI) driven intrusion targeting Thailand’s Ministry of Finance, indicating possible exposure to ministry information. Threat actors used open-source AI tools such as Hermes and Hades AI agents to automate complex cyberattacks.

Logs recovered show that the operator instructed the AI agents to enumerate files from a content directory, essentially showing records associated with the Office of Permanent Secretary of Finance. But researchers noted that no evidence indicates that files were exfiltrated. 

While no official attribution has been made, the researchers assessed with low-to-medium confidence that the threat actors are of Chinese origin based on factors such as geographical basing, Chinese language artifacts found during investigation, and tool and infrastructure selection, much of which are China-specific.

As of writing, researchers stated that the Thai government has been informed of the intrusion, but has not officially confirmed the incident.

Proliferation of AI Integration in the Cyber Kill Chain

Interestingly, the entire attack sequence was found to be managed autonomously by Hermes AI agent with its unrestricted “YOLO” operation with Hades serving as an implant for long-term persistence. This adds to the growing body of knowledge with regards to integrating AI within the cyber kill chain

Palo Alto Networks' Unit 42 researchers recently disclosed another instance of AI used for automating attack chains, as a Chinese-speaking actor was tracked using a known Chinese AI model, DeepSeek, with Hermes AI agent serving as framework. The threat actor let the system hunt vulnerabilities online with the intention of also exploiting the code to launch attacks without human inputs. 

PSA Intelligence assesses that AI integration in offensive cyber operations will be commonplace moving forward. The increasing availability of powerful AI models along with accessibility to various cybersecurity focused open-source tools will expand the scale and acceleration of cyber operations moving forward. Furthermore, defending against autonomous AI-driven attacks requires a rethinking of fundamental security models. Traditional security models assume threat actors take considerable time to explore and exploit a network. AI-driven tools considerably reduce the timeline that traditional early warning systems may not be able to track, creating a visibility gap that organizations must fill. 

China-Linked JadeProx Campaign Targets Government and Healthcare in Asia and Latin America, Further Highlights threat of Impersonation Attacks

Cybersecurity researchers at Group-IB disclosed a China-linked campaign targeting Government and Healthcare sectors across East and Southeast Asia as well as Latin America. The campaign was labeled as JadeProx and is known to use a new windows-specific malware called TriBack loader.

Amongst the targeted entities are: a Vietnamese hospital, Malaysia’s Ministry of Foreign Affairs, Hong Kong’s education infrastructure, and Honduras’ National Congress, with also a trace from a Venezuelan local government.

JadeProx victim map. Illustration by Group-IB, 2026

In Hong Kong, the threat actors exploited WordPress Photo Gallery plugins and data management systems ASUSTOR ADM. While in Venezuela, the threat actors impersonated a domain used by a municipal tax system and managed to collect personal documents and payment records. 

Furthermore, in a LinkedIn post by Dmitry Volkov, one of the Group-IB’s researchers, the threat actors created a fake Claude Pro AI software installer as a phishing bait, indicating how threat actors weaponize legitimate, popular applications to manipulate and compromise unsuspecting targets.

Fake Claude-Pro website and installer used as a phishing bait. Photo by Dmitry Volkov, 2026

The Mechanics of Impersonation Attacks

Impersonation Attacks can be defined as a social engineering vector where cyber threat actors pose as trusted entities in order to exploit human psychology with the aim to influence and deceive. 

Cyber threat actors routinely evolve their operational tactics, techniques, and procedures (TTPs) in order to adapt to the contemporary trends and fads. As such threat actors typically involve social engineering methods by adapting their attack patterns in accordance to a certain environmental context. This follows PSA Intelligence’s running belief that human-centric risks are proving to be more challenging critical security risks than traditional technical vectors. 

Impersonation Attacks have four distinct phase: 

  1. Reconnaissance - Threat actors meticulously studies its victims, aiming to build patterns of behavior and points of vulnerabilities.
  2. Infrastructure Setup - Based on collected information, threat actors build and stage vectors to appear as legitimate actors, such as typosquatting and lookalike domains. 
  3. Social Engineering - Threat actors will create or force a trigger a trusted relationship that would influence and expose the subject/s into doing something. 
  4. Exploitation - Once trust is established, the attack will continue to achieve its other operational objectives such as credential and information harvesting, email compromise, and/or malware injection.

To mitigate this, PSA Intelligence advises users to exercise caution when interacting with unsolicited mails, messages, and prompts, carefully inspect every bit of information pertaining to branding and organizational personality to ensure authenticity. 

South Korea Investigates Possible Data Breach Targeting Diplomatic Academy, Indicating Possible North Korean Cyber Intrusion

South Korean officials at the Ministry of Foreign Affairs (MOFA) recently disclosed a data breach likely linked to North Korean actors against the National Diplomatic Academy's (KNDA) web-based learning infrastructure, an incident that potentially compromised roughly 10,000 datasets belonging to over 6,000 users throughout a ten-month window.

According to South Korean officials, the campaign spanned from April 2025 through February 2026. Following the discovery, MOFA shut down the affected systems and had reportedly initiated an update of staff authentication credentials to mitigate further risk.

South Korean authorities have yet to disclose proper technical evidence of the attack. However, PSA Intelligence assesses that the targeted nature of the campaign is indicative of intelligence gathering initiatives by North Korean cyber threat actors 

According to South Korea's National Intelligence Service, North Korean threat actors accounted for over 80 percent of public sector cyberattacks in 2023. State-sponsored Advanced Persistent Threat (APT) groups under North Korean intelligence units, such as Lazarus (APT38), Ricochet Chollima (APT37), and Kimsuky (APT43), were known to frequently target South Korea’s public institutions.

In 2022, South Korea also uncovered a similar campaign targeting diplomats and foreign policy experts. The threat actors used the stolen personally identifiable information (PII) obtained through social engineering and spear-phishing methods to carry out ransomware attacks. Analysts note that the recent campaign used a more technically sophisticated zero-day exploit within the KNDA’s server, leading to persistent control and access over the system, exposing user IDs, names, emails, and passwords. 

PSA Intelligence notes that the recent incident had seemingly contributed to the reform of South Korea’s personal data protection law, which was signed in March 2026 and will take effect in September 2026. The reforms introduced a supervisory liability for both public and private organizations. The reform also establishes an early notification mechanism requiring organizations to immediately notify individuals affected within 72 hours of a possibility of breach; this also introduces an increased fine of 10 percent of total revenue for organizations that were found to have severe corporate data protection failures

Cybersecurity Threat Landscape

CISA Warns of Surge In Cyberattacks Targeting US Water Systems

The United States (US) Cybersecurity and Infrastructure Security Agency (CISA) issued a warning regarding a spike in cyberattacks targeting water and wastewater systems. The alert comes in response to a coordinated cyber attack from June 26 to 27, 2026 that disrupted the operations of more than 30 community water facilities in Minnesota. 

Threat actors are targeting programmable logic controllers (PLCs) and other operational technology (OT) systems that are exposed to the public internet. According to the advisory, threat actors have been locking operators out of these systems by modifying passwords and altering IP addresses to disconnect the devices. This activity has reportedly caused equipment malfunctions, forced some utilities to switch to manual operations, and in some cases, led to “boil water notices” for some communities. 

According to CISA, water facilities of all sizes are at risk, including those with mature cybersecurity defenses. One specific entry vector highlighted by the agency is the presence of undocumented cellular modems, often installed by vendors or operators, which create blind spots that bypass routine attack surface scans. Cybersecurity firm Censys estimates that globally, there are currently thousands of internet-exposed PLCs from vendors like Rockwell Automation, Siemens, and Schneider Electric, many operating on end-of-sale firmware or connecting via commercial cellular and satellite networks. 

Vendor Equipment and Exposed Instances

  • Rockwell Automation/Allen-Bradley: 4,100
  • Siemens: 4,100
  • Schneider Electric: 2,000

CISA urges critical infrastructure owners to immediately disconnect PLCs and other OT systems from direct internet access. If remote connectivity is needed, organizations should implement virtual private networks (VPNs). Additionally, utilities are advised to update default passwords, restrict access using only allowed IP addresses, and maintain offline backups of PLC configurations to restore operations in the event of a compromise. 

PSA Intelligence notes that while the recent CISA advisory does not attribute this specific campaign to a known threat actor or geographic origin, there is a documented precedent for such activity. Historically, Iranian-linked threat actors have actively targeted US water and wastewater systems. Previous advisories have highlighted state-sponsored threat actors scanning for and exploiting internet-exposed PLCs. Unlike financially motivated cybercriminals deploying ransomware, nation-state actors typically target critical infrastructure to probe defense capabilities, establish persistent access, and demonstrate the capacity to cause operational disruption.

AI on the Offensive: OpenAI Model Escapes Test Environment, Anthropic and Meta Models Implicated in Misconfiguration Breaches

Recent cybersecurity incidents have implicated artificial intelligence (AI) models from OpenAI, Anthropic, and Meta after they interacted with real-world systems during testing. An OpenAI model broke out of its testing environment or ‘sandbox’ by exploiting a chain of zero-day vulnerabilities. Meanwhile, three Anthropic models and Meta’s Muse Spark 1.1 targeted real companies after a misconfiguration in their sandbox granted them full internet access.

OpenAI Models Exploit Zero-Day Vulnerabilities

In July 2026, an OpenAI model escaped out of its test environment while the company was testing the offensive cybersecurity capabilities of some of its models. Because the models were in a restricted environment with limited internet access, standard safety guardrails had been disabled. However, by chaining zero-day vulnerabilities found in the environment’s Artifactory proxy, the models successfully moved across OpenAI’s internal network until they secured outward internet access. 

This access allowed the model to target Hugging Face, an open-source company known to host AI models and datasets. Once online, the model reasoned that the company likely had the answer to OpenAI’s test. It then broke into its production server and pulled out the information it needed to solve the exercise. Hugging Face disclosed the breach  on June 16 and reported the incident to local law enforcement before identifying OpenAI as the culprit. The company noted that the consequence of the breach was limited in nature and that both companies have partnered with each other to address the issue. 

More Reading: Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident

Anthropic and Meta Models Escape after Sandbox Misconfiguration 

Anthropic: Opus 4.7, Mythos 5, Internal Research Model

In a similar cybersecurity offensive evaluation, Anthropic disclosed that three of their AI models targeted three undisclosed organizations. Unlike the OpenAI incident, these models did not “deliberately escape the test environment” but were able to break out because of human error. Three of Anthropic's models, Opus 4.7, Mythos 5, and an internal research test model were given a capture-the-flag (CTF) challenge to test their hacking capabilities. 

The models were told that they were in a simulation with no internet access. But because of a misconfiguration caused by a third-party evaluation partner, Irregular, internet access was made available which allowed them to target the organizations, believing that it was still in a simulation. Each model searched for “basic” vulnerabilities such as weak passwords and unauthenticated endpoints. This tells us that several organizations still lack certain cybersecurity practices in place. 

Claude Opus 4.7

The model’s fictional target happened to share the name of a real organization, leading the model to target that company. Opus 4.7 conducted four runs and was able to extract application and infrastructure credentials. The model recognized later on that it was no longer in a simulated environment but continued the attack nonetheless. 

Claude Mythos 5

Mythos 5 published a malicious Python package under a fake developer name; it was public for 1 hour and was installed on 15 real systems, leading to infrastructure access and credential theft. The model emphasized that a real-world attack is unacceptable and continued to reason that it was still in a simulated environment. 

Internal Research Model

An internal research model was tasked to target a fictional organization. But, as it could not reach the target, it instead scanned 9,000 targets and identified a company with a vulnerable internet-facing application. The model later realized that it was in a “real cloud account” and stopped the attack. 

Meta Muse Spark 1.1

Similar to Anthropic, Meta’s Muse Spark 1.1 model was able to access the public internet and breach an undisclosed organization because of a misconfiguration caused by Irregular, an evaluation partner of Anthropic. This marks the latest incident of AI attacking organizations as of writing. After gaining access to the internet, the model exploited a vulnerability which allowed it to gain access to an organization’s internal  systems. Meta has not released a statement as of writing. 

More Reading: A benchmark for evaluating the cybersecurity capabilities and risks of language models.

Assessing the Real-World Threat of Autonomous AI

A report published by the AI Security Institute (AISI) notes that during routine evaluations, certain models from Anthropic and OpenAI “engaged in sustained, potentially harmful activity directed at real people and organisations.” While human oversight remains a necessary part of the process, and although “investigations have not evidenced any resulting real-world harm” yet, the ability of these AI models to utilize autonomy and deception without specific prompts is highly concerning. 

Although initially intended to be confined to simulated environments to test their offensive capabilities, a misconfiguration by human testers inadvertently connected the Anthropic and Meta models to the internet, leading them to autonomously target real-world companies. Conversely, the OpenAI model defeated its containment. Experts warn that unless “strong safeguards” are in place, these incidents will continue to add to a growing number of AI-driven cyberattacks, a trend which analysts expect to increase as AI continues to be adopted and developed. 

PSA Intelligence notes that AI capabilities continue to surpass current human-designed containment strategies. Recent incidents have demonstrated how AI agents have successfully identified backdoors and zero-day flaws to escape containment. This proves an urgent need for organizations to establish more robust security teams and provide protocols to review sandbox checks before deploying AI models for testing.  Simultaneously, certain AI models are demonstrating the ability to autonomously discover vulnerabilities at a fraction of the traditional computing cost. These advancements will continue to lower the technical barrier to entry for threat actors and compress the “patch gap,” allowing them to weaponize vulnerabilities almost immediately after disclosure and making software updates an even more essential part of security. 

More Reading: Incident Report: unsanctioned agent behaviour during cyber testing

Microsoft Disclosed Russia-Linked Campaign Targeting Hotel Wifi Networks for Cyber Espionage

Microsoft recently released a report detailing an alleged Russian state-sponsored campaign compromising hotel Wi-Fi networks around the world with the aim of conducting cyber espionage.

The report comes after another cybersecurity firm, ReliaQuest, disclosed similar activity back in July, noting that the campaign primarily targets hotels in the US, as well as in Saudi Arabia and India. 

The researchers said that attackers exploit the internet traffic to target online-facing Microsoft services such as Microsoft365, redirecting users to fake Microsoft login pages in order to obtain login credentials.

While both firms agreed that the campaign is directly attributed to Russian state actors, both differ in their assessment of the primary threat actor. Microsoft believes that the campaign is orchestrated by Cozy Bear (APT29), an advanced persistent threat (APT) group linked to Russia’s Foreign Intelligence Service (SVR). However, ReliaQuest instead attributed the campaign to Fancy Bear (APT28) linked to Russian military intelligence (GRU). PSA Intelligence notes that both threat groups are known for covert intelligence gathering abroad. 

Intelligence-Driven Targeting 

PSA Intelligence notes that cyber targeting in the hospitality sector is rarely opportunistic. Specific campaigns targeting hotels in the US mainland fit in with known Russian and Chinese intelligence operations targeting key individuals with significant ties and links to US government and lucrative private sector enterprises. 

The campaign is similar to a cyber-espionage campaign tracked as “DarkHotel” that has been active since 2004. The campaign is known to target luxury hotel networks as vehicles to gain access to selected high-profile victims. Furthermore, cases of botnet-style operations have also been lodged in the same campaign, and are primarily used for mass surveillance. 

The victim profile typically focuses on narrow demographics; aside from traditional politicians, it includes arms control and medical watchdog personnel, international sports doping bodies, and energy policymakers. 

Recommendations

PSA Intelligence advises clients to always treat all public, hotel, conference, and airport Wi-Fi networks as compromised; they should be avoided whenever possible. Users must prioritize private connectivity, either through mobile data services or by deploying travel routers when traveling. 

Moreover, augment passwords with passwordless multi-factor authentication (MFA), such as additional biometric and device-enabled authentication layers, especially for high-value and privileged accounts. This creates another layer that is resistant against potential phishing attacks. 

Cybersecurity Vulnerabilities

Fake AI-Generated Vulnerability Reports Flood CVE Pipeline

A recent report from cybersecurity firm JFrog flagged a concerning issue with how fake artificial intelligence (AI)-generated vulnerabilities are starting to surface and flood the Common Vulnerabilities and Exposures (CVE) database. 

The issue escalated when a newly created GitHub account published 54 vulnerability advisories targeting SQLite. These reports appeared highly credible, prompting MITRE to assign them official CVE identifiers. Several were immediately categorized as critical, with one flaw (CVE-2026-51302) initially receiving a maximum severity score of 10.0. 

However, an investigation conducted by JFrog security researchers revealed that 54 out of the 55 reported SQLite vulnerabilities were entirely fabricated by AI. According to the researchers, the AI-generated advisories cited non-existent functions and referenced code that did not exist in the targeted SQLite version. Additionally, none of the provided Proof of Concept (PoC) payloads actually functioned or triggered any memory crashes. 

A review of the CVE entries in the National Vulnerability Database (NVD) shows that these vulnerabilities are now marked as “Rejected” with a “Do not use this CVE record” message.

CVE-2026-51302 flagged as rejected after being discovered as fake | Source: NIST NVD

This incident exposes flaws in how the industry ingests vulnerability data. The public CVE submission process currently lacks identity verification or mandatory PoC requirements. Historically, the NVD run by the National Institute of Standards and Technology (NIST) manually validated submissions. However, since NIST paused its deep analysis in 2024 due to a massive backlog and recently updated its vulnerability categorization process on April 15, 2026, plausible-sounding but fake advisories can now slip directly into databases and enterprise scanners. 

These fake CVEs force security teams to waste valuable resources investigating phantom threats. The flooding of the vulnerability pipelines with fake vulnerabilities poses a significant risk, particularly as automated AI security tools may attempt to triage or patch code that doesn’t actually exist, distracting organizations from remediating genuine vulnerabilities. 

More Reading: SQLite Critical CVEs or LLM Slop?

Subscribe to CyberSecurity.PH

Subscribe to receive our latest updates as they get released.
[email protected]
Subscribe