CyberSecurity.PH #045
This brief covers threat actors exploiting remote access vulnerabilities from hidden back to access cameras of military drones to the disruption of critical infrastructure across continents. We also tackle how North Korea exploits remote work; and urgent security updates for consumer technology.
CyberSecurity.PH is now supported by the PSA Intelligence Cyber Risks
APAC and Philippines
Analysis on UK Navy Drones Camera Sent Data Back to China
The Telegraph had disclosed an incident during a routine cyber vulnerability test where a United Kingdom’s (UK) Royal Navy maritime drones were found to have sent data back to a device in China. The UK’s Ministry of Defense (MoD) had stated that it severed the internet connection of the drones in order to contain the issue, the ministry also stated that while external connections were found, no evidence that a sensitive data breach occurred.
Moreover, the drones in question are the recently acquired fleet of K3 Scout surveillance drones which were originally procured back in March 2026. The authorities attributed the vulnerability to a Chinese-made component within the cameras of the drones. The component allegedly sent an automated network ping, called a “squark”, back to an IP address in China. The authorities did not specifically detail what had been sent, but depending on the system, a squark can theoretically transmit either telemetry or location information.
Third-Party Components and Global Supply Chain Risks to National Security
Kraken Technology Group, the K3 drones manufacturer, said that the cameras were in fact procured from a third-party supplier with components originating outside of the UK. The investigation revealed that the compromised camera subsystem fitted in the drones, is sending automatic data signals confirming its status back to China. The unauthorized connection was exploited through a supply-chain vulnerability, embedding custom instructions through the camera's built-in firmware rather than an active cyber infiltration.
While no official pronouncements denouncing espionage have been made by UK authorities as of yet, the incident raises a question on procuring modern technologies of foreign origin, especially in use cases adjacent to a nation’s national security.
China’s manufacturing capabilities in particular have enabled the country to achieve a dominant position within the global electronics market. Its characteristically strong industrial clustering and vertical integration has cultivated a robust system of integrated manufacturers. This ecosystem facilitates an exceptionally close relationship between industry players and state apparatuses, a strategy formally recognized as Military-Civil Fusion (MCF). Consequently, PSA Intelligence believes that the recent drone incident showcases the manner in which Beijing’s MCF mandate can successfully exploit the global commercial supply chain to advance China’s strategic national objectives.
Furthermore, as commercial manufacturing and private technology-transfer networks are deeply integrated with state security apparatuses, Western procurement of seemingly compliant commercial components from Chinese suppliers creates a backdoor for passive state espionage. As such, Western nations, with the lead of the US, are actively pushing trade controls and outright prohibition of procuring advanced technology from China due to associated national security concerns.
Understanding how CCTV Systems can be exploited
Modern IP-based closed-circuit televisions (CCTV) are vulnerable to remote exploitation through weak Domain Name System (DNS) configurations, unpatched and outdated firmware, as well as vulnerabilities associated with third-party components can compromise both digital and physical systems and can likewise increase security costs for end users.
The infographic below shows general risks and advice regarding CCTV systems:


PSA Intelligence recommends that enterprise risk management teams handling sensitive or classified materials reassess their risk exposure to third party vendors and procurement policies. Risk management teams who assess their business to be at high risk from espionage threats will benefit from involving security practitioners in the procurement process for equipment intended to safeguard sensitive or classified materials.
Recent AI-Enabled Cyberattack on Taiwan Sheds Light on Evolving Role of AI In State-Sponsored Cyberattacks
Dream, an Israeli artificial intelligence (AI) firm, had published a report documenting an AI-enabled near-autonomous cyberattack aimed at Taiwan’s government agencies last month. The report revealed threat actors had accessed 85 accounts, extracted more than 2500 personnel records, and mapped 21 government systems in the span of four days, believed to be between July 1 and 4.
A day after the publication of the report, Taiwan’s Ministry of Digital Affairs confirmed the AI-assisted attacks on its government agencies, but also asserted that the affected government agencies had managed the issue successfully. The statements made by the authorities in Taiwan did not specifically mention China. However, similar attack patterns across East and Southeast Asia suggest that threat actors based in either North Korea or China lead in testing new attack frameworks using AI.
PSA Intelligence notes that earlier this year, Taiwan’s National Security Bureau released a report indicating that China-borne cyberattacks on Taiwan had climbed 6% in 2025. The report also indicates that a consistent pattern has emerged where selected cyberattacks against Taiwan are linked to important political and military events, suggesting coordinated multi-dimensional pressure against the island state. Moreover, it must be noted that China’s Law on Promoting Ethnic Unity and Progress officially took effect on July 1, possibly mirroring the timeline of the cyberattacks on top of increases in maritime patrols.
Growing Threat of AI Attacks & Evolving Nature of State-Sponsored Cyberattacks
In a recent CrowdStrike 2026 Threat Hunting Report, AI-enabled attacks are becoming the most defining feature of the cybersecurity space in 2026. The report findings also show the dual edge nature of AI systems. While threat actors increasingly used frameworks with AI systems for offensive cyber operations, organizations are simultaneously using AI for defensive cyber operations.
The rise of AI-enabled cyberattacks has fundamentally enhanced the cyber kill chain framework in multiple aspects, primarily in speed and scale of attacks. Currently, developments are still ongoing to properly leash unstable AI-related vulnerabilities.
However, the unstable nature of current AI models may also be exploited by nation-states looking to conceal their actions behind plausibly deniable attacks. Russia, for instance, is actively deploying AI-enabled offensive systems in Ukraine, according to Computer Emergency Response Team of Ukraine (CERT-UA); moreover, Iran is utilizing readily available AI models in order to gain asymmetric advantage over the United States amidst ongoing crisis in the Middle East.
PSA Intelligence is monitoring the evolving threat landscape of AI enabled cyberattacks. As of this report there is not enough data to pinpoint how widespread this has been adopted by state-sponsored actors in parallel to geopolitical flashpoints.
East Timor to Combat Online Scam Networks Underscores Regional Momentum Against Organized Cybercrime
On August 5, 2026, the Government of East Timor had approved a plan to curb organized cybercrime, illicit online scam networks, and human trafficking between 2026 and 2031. Included in the national plan is the establishment of a permanent coordination mechanism under the country’s executive office.
The plan was proposed by East Timor’s Interior Ministry, and is said to be a reaction against growing digital fraud operations across Southeast Asia which are seen to pose national, economic, and social risks to East Timor. PSA Intelligence notes that East Timor performed a series of raids against online scam hubs in the last few months.
Across Southeast Asia, adjacent policy developments have gained momentum; notably, Cambodia ratified an Anti-Online Scam Law last April, following intense pressure regarding lawless compound operations. Similarly, the Thai government recently granted authority to its money laundering regulators to reimburse fraud victims using confiscated assets, effectively streamlining recovery by side-stepping lengthy judicial processes.
In a parallel move, Singapore passed amendments to its anti-scam law to tighten grip on platform accountability, mandating robust defenses against digital deception and malicious cyber activity aimed at its citizens. Moreover, it must also be noted that as of recently, the Philippine government had also intensified crackdown on local scam hubs and illegal gambling sites, effectively matching regional efforts to curb scam activities.
PSA Intelligence notes that Southeast Asia is currently considered to have the largest concentration of cyber scam hubs and human trafficking-fueled fraud operations. In a report released by the Office of the High Commissioner for Human Rights earlier this year, more than 300,000 people are trapped and trafficked into scam centers across Southeast Asia. This exemplifies the massive scale and transnational nature of online scams in the region.
Cybersecurity Threat Landscape
CISA Releases Updated Joint Advisory on Medusa Ransomware Group, Over 500 Organizations Hit
On August 18, 2026, the United States (US) Federal Bureau of Investigation (FBI), US Cybersecurity and Infrastructure Security Agency (CISA), and US Department of Health and Human Services (HHS) released an updated joint advisory regarding the Medusa ransomware operations. As of April 2026, the cybercrime operation has impacted over 500 critical infrastructure organizations spanning government services, healthcare, defense, IT, manufacturing, and financial services.
The Medusa Ransomware Group: Who are they?
Medusa is a financially motivated cybercriminal operation known for ransomware campaigns targeting vulnerable web-facing assets and employing a “double-extortion model” where the stolen data is encrypted and publicly released unless a ransom is paid. The group relies on initial access brokers (IABs) in cybercrime forums to identify potential victims and is known to employ phishing campaigns and aggressively exploit unpatched software.
The group was first observed in 2021 as a closed ransomware variant - meaning that a small group of threat actors controlled the malware development and distribution. The operation then progressed to a ransomware-as-a-service (RaaS) model in 2023, launching a dark web leak site to weaponize stolen data and pressure organizations into paying ransom. In 2026, the group operated more aggressively and “opportunistically,” leveraging “newly announced exploits before potential victims can mitigate vulnerabilities through patching” as observed in the exploitation of Common Vulnerabilities and Exposures (CVE) 2026-1731 in February 2026.
PhilHealth Incident (2023)
State-owned Philippine Health Insurance Corporation (PhilHealth) was targeted by Medusa in September 2023, compromising the data of its users and employees, with Medusa demanding a ransom of USD 300,000 (PHP 17 million) which PhilHealth declined to pay. Investigations conducted by PhilHealth and the Department of Information and Communications Technology (DICT) revealed that an outdated antivirus software, which had expired on April 15, 2023, was identified as the entry vector that made the attack possible - showing that the antivirus had not been updated for 4 months.
Importance of Updating Software and Devices
PSA Intelligence emphasizes the importance of timely patch management as it eliminates the known software or device vulnerabilities that threat actors rely on. Although patching cannot protect against unknown zero-day threats, promptly updating devices is a good practice and stops threat actors from exploiting recognized vulnerabilities. For high profile individuals or organizations, postponing these updates prolong their risk exposure, essentially inviting attackers to exploit vulnerabilities that have already been resolved.
Enable automatic updates to ensure that devices receive the latest security patches immediately. If manual updates are preferred, set a reminder to check for them on a regular basis.
A Look into Famous Chollima’s Fake IT Worker Hiring Scam
An undercover sting conducted by cybersecurity company ANY.RUN offers a deeper insight into the operational tactics of North Korean IT workers infiltrating global business. Disguised as legitimate tech professionals, these operatives, often linked to the Lazarus group (specifically the “Famous Chollima” division), secure employment to funnel funds back to the Democratic People’s Republic of Korea (DPRK), steal proprietary source code, and compromise internal systems.
How Do They Get In?
To infiltrate organizations, these fake workers use a variety of deceptive techniques. Researchers note the use of generative artificial intelligence (AI) to forge realistic identity documents - though researchers note that they sometimes leave traces like AI watermarks. They also rely on stolen or leaked identities and use Virtual Private Networks (VPNs) like AstrillVPN to mask their true locations.

During the interview phase, operatives frequently utilize AI assistance and live translation software to overcome language barriers. They also use a “referral” technique, recommending other operatives for open roles to form an internal network. Once onboarded, they employ tools like ChatGPT for coding assistance and Google Remote Desktop to maintain persistent access, quietly embedding themselves in the organization for months or years to access intellectual property or influence code reviews. Notably, these tools represent only a fraction of their broader operational arsenal.
Why is this Important for HR or Hiring Teams
For Human Resource (HR) and hiring teams, this changes the recruitment landscape particularly for remote workers. While the primary intent of these operatives is to secure remote jobs to funnel money back to the DPRK, the threat extends far beyond this. There is a severe risk for Information and Communication Technology (ICT) companies that serve as government contractors. Infiltrating these vendors expose organizations to state-sponsored espionage and jeopodizes sensitive or classified government information.
Traditional background checks and right-to-work screenings are no longer sufficient, as these operatives actively exploit the gaps between identity verification. Hiring teams are advised to collaborate with security teams to identify subtle red flags, such as conflicting identifying details, visible AI artifacts on documents, and visibly assisted interview behavior (frequent off-screen glances).
Organizations are advised to treat hiring verification as a continuous security process. Risk management teams should evaluate remote positions and considering mandating in-office work
Iran-Linked Cyberattacks Expand to Water Utilities in New Jersey and Alabama
A wave of coordinated cyberattacks targeting United States (US) water and wastewater facilities continues to expand, with confirmed incidents now reaching at least 12 states. Initially reported in July 2026 by facilities in Minnesota, the attacks have since spread to states including Michigan, South Dakota, Georgia, New Jersey, and Alabama. While recent advisories from the Cybersecurity Infrastructure and Security Agency (CISA) do not attribute this specific campaign to a known threat actor or geographic origin, multiple sources and federal advisories indicate that Iranian-linked threat actors are behind the campaign.
Tactics utilized by threat actors involve scanning the internet for exposed operational technology (OT), specifically targeting programmable logic controllers (PLCs) manufactured by Rockwell Automation, Siemens, and Schneider Electric. By gaining remote access to these devices, threat actors can alter settings, change default passwords, and lock facility operators out of their own monitoring systems.
While the intent appears to be disruptive, the impacts have remained limited so far. In New Jersey and Alabama, affected facilities were forced to temporarily disconnect their systems and operate manually, but water quality and safety were not compromised. In Georgia, a precautionary boil water advisory was issued but quickly lifted after testing. The Federal Bureau of Investigation (FBI) and CISA continue to advise water facilities to disconnect PLCs from direct internet exposure and update default passwords to mitigate the threat.
PSA Intelligence highlights that Iranian-backed cyber operatives have a documented history of targeting US water and wastewater facilities. These state-linked cyberattacks remain directed at nations directly involved in the kinetic conflict with Iran, wherein these groups breach critical infrastructure to probe security blind spots, establish backdoors, and demonstrate their capacity to inflict physical and operational damage.
Cybersecurity Vulnerabilities
Microsoft’s Monthly Patch - August 2026: 400 Vulnerabilities Fixed, Including 3 Zero-Days
Microsoft released its August 2026 update, which delivers fixes for 400 vulnerabilities and addresses three zero-day vulnerabilities.
The highlights of the patch include:
Addressing three zero-days, including one actively exploited in attacks and two publicly disclosed. The actively exploited vulnerability is a Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability, identified as Common Vulnerabilities and Exposures (CVE) 2026-68820. CVE-2026-68820 stems from a use-after-free vulnerability that allows an unauthorized attacker to elevate privileges locally to gain SYSTEM privileges without user interaction.
The publicly disclosed zero-days are a Windows User Profile Service Elevation of Privilege Vulnerability (CVE-2026-62832) and a Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability (CVE-2026-72971). CVE-2026-62832, also known as "LegacyHive," allows an authenticated attacker to load another user's registry hive to gain administrator privileges. CVE-2026-72971 also allows an authenticated attacker to perform tampering locally and gain administrator privileges without user interaction.
Addressing 42 "Critical" vulnerabilities. These include 37 remote code execution (RCE) flaws and 5 elevation of privilege flaws. Overall, the 400 flaws consist of 176 elevation of privilege, 110 RCE, 86 information disclosure, 12 denial of service, 11 security feature bypass, and 21 spoofing vulnerabilities.
Several vendors, including Adobe, Cisco, Metabase, N-able, SAP, TP-Link, and VMware have also released important security updates in August 2026.
Administrators are advised to prioritize applying patches to vulnerable instances. The list of all vulnerabilities patched for the August 2026 update can be found here.
Cyber Risks to Monitor
Apple Issues Threat Notification Against Users Affected by ‘Mercenary Software’ Spyware Attack
Apple recently disclosed a threat notification regarding “Mercenary Software” and spyware attacks targeting high-risk and high-profile Apple users on August 13, 2026. Apple’s threat notification urged select iPhone users across 110 countries to enable lockdown mode to take necessary steps to protect their personal information and to contact Apple’s 24-hours digital service hotline.
Apple recently disclosed a threat notification regarding “Mercenary Software” and spyware attacks targeting high-risk and high-profile Apple users on August 13, 2026. Apple’s threat notification urged select iPhone users across 110 countries to enable lockdown mode to take necessary steps to protect their personal information and to contact Apple’s 24-hours digital service hotline.
Details of the Threat Notification
The threat notification was published following concerns of a “Mercenary Software”, which are associated with state-sponsored actors, who specifically target high-profile individuals such as politicians, diplomats, activists, journalists, and Non-governmental organizations (NGOs). These attacks are similar to the Israel-based NSO group, Pegasus Software that infected the device of a European parliament member tasked with investigating the spyware from 2022 to 2023. Apple stated that receiving a threat notification does not indicate their device was hacked. The notification was a high-confidence warning that the individual is a likely target.
Spyware attacks can infiltrate targeted devices through zero-click URLs, where the targeted device is infected upon receiving a message. Spywares have the capacity to intercept messages despite using encrypted messaging platforms such as Signal or WhatsApp. Apple stated that it had notified users across 150 countries since the launch of Apple’s threat notification program since it began in 2021.
The Importance of Keeping Your Devices Updates
PSA Intelligence emphasizes the importance of keeping software and devices up to date with the latest security patches, as these close the specific software vulnerabilities required to trigger exploits. While patching does not completely prevent undiscovered vulnerabilities, a timely patch management prevents attacks that target known, unpatched gaps in a system or device. For high profile targets, delaying updates expands the window of vulnerabilities, giving threat actors a way to exploit security flaws.
