CyberSecurity.PH #047

In Central Asia, hundreds of fake government websites are uncovered. Over 220 million travel records exposed from Vietnam's travel database. VPN flaw compromises government personnel records of Japan. And critical security updates for Microsoft and Apple users

CTA Image

CyberSecurity.PH is now supported by the PSA Intelligence Cyber Risks

Learn more

APAC and Philippines

Hundreds of Fake Government Websites Mimicking Social Assistance Programs in Central Asia

Cybersecurity firm F6 uncovered a wide-ranging phishing campaign using over 360 fake government domains targeting people in Central Asia. The campaign leverages traditional social engineering methods such as mimicking and fabricating government social programs in order to steal personal information from its victims. 

The campaign has been identified in countries such as Uzbekistan, Belarus, and Tajikistan. However, the researchers noted that the identity of the responsible cyber threat actors is yet to be determined. PSA Intelligence assesses that it is more than likely that known financially motivated syndicates in Central Asia, such as those part of the Russian-speaking call-center and bank fraud networks, are likely responsible for the attack.

Sample of a fake landing page for registering with a social program: Translated through Google Translate. Photo from F6, 2026

The campaign primarily relies on simulating government-backed social programs offering citizens monetary assistance and a way to get passive income, offering as much as USD 1,300 (PHP 81,569) in countries such as Uzbekistan. But in order to claim the money, victims are asked to provide personally identifiable information (PII) such as their name and phone number. The threat actors would then use this information to directly contact the victims through a call posing as “personal managers,” typically soliciting “commissions” in return. In some cases, threat actors have managed to gain full control of the victims’ devices and accounts through malicious app installation. 

PSA Intelligence notes that the exploits and methods used in the campaign are similar to vectors used by Southeast Asia-based scam-center syndicates. These kinds of operations typically utilize malware-as-a-service (MaaS) models, where malware infrastructure and support tools are leased and widely shared to cybercrime networks resulting in similar tooling and vector patterns. 

Moreover, regional operations can also enable scalability of attacks, increasing the likelihood of dispersion across Central Asia as the campaign uses trusted state-programs that are largely uniform across the region. 

PSA Intelligence advises clients operating in this area to take the following precautionary measures: 

  • Unverified App Installation: Never install mobile applications outside official app stores for program registration, and treat identity-document uploads demanded by unofficial channels as fraud indicators. 
  • Enforce Multi-Factor Authentication (MFA) & Passkeys: Implement phishing-resistant authentication methods such as passkeys or hardware tokens for all company devices to render stolen credentials useless.

Over 220 Million Travel Records Exposed via Misconfigured Vietnam Database

Cybersecurity researchers at Kinryū Labs discovered an exposed Advance Passenger Information System (APIS) database hosted in Vietnam, likely containing records of more than 220 million passengers and crew members, including associated flight details, due to lapses and misconfigurations in admin access.

APIS is a regulatory data system through which airlines transmit passenger and crew manifest details to border and security authorities before departure.

Researchers noted that they could not confirm which Vietnamese organization operated the database nor whether it was a victim of a ransomware attack, as researchers found no traces of misuse during their initial investigation. However, the researchers said that Vietnamese authorities had been informed of the incident as early as June 3, while access to the database was severed by June 8.

Exposed records covered travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others, across airlines spanning the Asia-Pacific, Europe, and the Middle East, totaling over 107 GB of data. 

Screen capture of the exposed database showing passenger and flight details. Image from Kinryū Labs, 2026

The exposed host shows a Vietnam Telecommunications (Viettel) assigned IP address and first became visible on the open internet in October 2022, before being flagged as a database in July 2023. Moreover, the exposed records span between 2017 and April 2026, meaning the true exposure duration is unknown

PSA Intelligence notes that the exposure does not exhibit any deliberate attempt at exploitation or attack, making the incident more than likely a result of a misconfiguration of the system.

Moreover, PSA Intelligence asserts that an identity-document dataset exposure of this scale is not uncommon. Cases such as First American Financial Corporation (2019), Verifications.io (2019), and the CAM4 incident (2020) had exposed upwards of 10 billion records. All of these incidents exhibit the same exposure vectors, such as public IP attachments and a lack of system authentication, as well as other overlooked security vulnerabilities.

Due to this, travelers and organizations should be wary of further exposure to fraud. As the researchers noted, there is currently no way of knowing whether the database was downloaded, copied, or sold elsewhere. Exposed passport details with a name, date of birth, and document expiration date are enough for phishing and document fraud attempts.


Japan's Digital Agency Discloses Non-Zero-Day Vulnerability in VPN Network Exposed 246,000 Personal Records

On September 11, 2026, Japan’s Digital Agency disclosed that it discovered a data breach caused by a non-zero-day vulnerability in its Virtual Private Network (VPN) appliance. It affected the agency’s Government Solution Service (GSS), shared by several Japanese government ministries and agencies. The breach exposed approximately 246,000 personal records, making it one of Japan’s largest reported data incidents this year. PSA Intelligence notes that the agency did not specify the exploited VPN product.

The Japanese government noted that the threat actor exploited a VPN vulnerability to gain unauthorized access to its servers. The actor accessed the system using a personnel account and retrieved a large number of files on the server. The agency noted that it detected unusual activity on June 25 and confirmed the exploitation by July 9. It subsequently suspended the account and severed external communications from compromised hardware. 

About 189,000 of the 246,000 leaked records belong to government employees using GSS, while the remaining 57,000 belong to contracted businesses and private individuals. In total, the breach exposed about 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and about 1,000 physical addresses. The agency stated it was aware of the vulnerability but had yet to apply a patch, and it warned the public against threat actors impersonating government employees. No other systems or public information were compromised in the attack. 

Japan’s Digital Agency Announcement on the VPN Vulnerability Attack (Machine-Translated). Illustration from Japan's Digital Agency, 2026

PSA Intelligence notes that the Japanese government did not disclose the specific attack methodology for this incident, and no threat actor was attributed to this incident. PSA Intelligence highlights its recent assessment showing Japan and Australia facing the highest concentration of cybersecurity incidents in the Asia-Pacific region (APAC). Furthermore, there are no indications of a geopolitically motivated threat actor being responsible for this data breach. Analysts note that the threat actors were likely motivated by criminal intent to sell leaked data to malicious entities. PSA Intelligence notes that threat actors with access to this data could potentially launch further phishing or social engineering attacks targeting sensitive institutions connected to the Japanese government.

Cybersecurity Threat Landscape

Joint Advisory on Iranian-Linked Threat Group Using Spyware to Target Journalists, Activists, and Dissidents

Iranian-linked threat actors are conducting global spear-phishing campaigns against Iranian dissidents, activists, and journalists via messaging platforms like WhatsApp and Telegram. In a joint advisory from the United Kingdom (UK) National Cyber Security Centre (NCSC), the United States (US) Federal Bureau of Investigation (FBI), and the Netherlands' General Intelligence and Security Service (AIVD), threat actors have been observed deploying a Windows-specific spyware identified as CHOSEN BRICK since 2025. A successful compromise grants the threat actors full surveillance capabilities over the compromised device, including screen capture, microphone access, and the exfiltration of private communications. 

Spear Phishing is a type of personalized cyberattack that specifically targets an individual or organization

The Attack Chain and Objectives

Initial access relies heavily on social engineering.  Threat actors conduct extensive open-source reconnaissance on their targets before initiating contact via messaging apps, often disguised as known acquaintances or technical support representatives. Their primary goal is to trick the victim into downloading the malicious software, which is typically disguised as a legitimate application or file. While threat actors prioritize compromising corporate devices, they will readily pivot to targeting a victim’s personal devices if their initial efforts fail.  

Once connection with the target device has been established, the malicious software “connects to Telegram for command and control” capabilities which allows the malicious software to “run commands through the native tools built into Windows” which allows them to do the following: 

  • Enumerate processes and system information 
  • Capture screen content and audio
  • Steal browser-based Telegram and WhatsApp data
  • Download secondary malware payloads
  • Exfiltrate email content
  • Delete files and wipe systems 

The advisory notes that while lateral movement has not been observed, “it is technically possible.”

Command and Control is a type of method used by threat actors use to communicate with compromised devices

Similar Trend

In May 2026, PSA Intelligence monitored a China-aligned cyber-espionage campaign with journalists and activists also being targets for the purpose of espionage.  This is relevant as it provides signals to support current assessments of China’s involvement in supporting Iran’s cyber capabilities. Specifically, the China-aligned espionage campaign, tracked as Shadow-Earth-053, which involves the exploitation of unpatched vulnerabilities and the conducting highly targeted phishing campaigns, illustrates an operational framework and capability that could substantially augment Iran’s own state-sponsored threat groups 

Recommendations

PSA Intelligence notes while this campaign is highly targeted, the underlying tactics, techniques, and procedures (TTPs) represent a universal threat often leveraged by broader cybercriminals and scammers. Threat actors frequently conduct reconnaissance using open-source intelligence (OSINT) and public social media profiles to customize their social engineering tactics to be more effective, underscoring the need to minimize one’s digital footprint. Furthermore, threat actors are known to frequently exploit popular messaging platforms to deliver malicious files via social engineering. 

Organizations are advised to instruct personnel to regularly audit their social media presence to limit the personal data attackers can use to craft highly convincing lures. Training must also highlight the risks of messaging apps by teaching users to identify spoofed contacts, avoid downloading unsolicited files, and consistently verify any unexpected requests or links through a secondary communication channel.

More Reading: Advisory on Iranian Cyber Targeting of Dissidents, Activists and Journalists | China-Linked Cyber-Espionage Operations Targeting Asian and NATO-Aligned Governments, Journalists, and Activists

Cyber Risks to Monitor

Apple Releases September Security Update Across iOS 27 and Other Apple Platforms

On September 14, Apple released major security software updates included in iOS 27, iPadOS 27, macOS Golden Gate 27, and other Apple platforms. The update prioritizes kernel-level fixes and resolves approximately 261 to 273 Common Vulnerabilities and Exposures (CVEs), ten of which relate to AI-assisted discovery fixes. Apple’s security notes stated that none of the listed vulnerabilities patched are currently exploited. 

One of the notable CVEs included in this update is CVE-2026-64752, which is a memory corruption flaw in CoreMedia that could allow threat actors to compromise an Apple device through a malicious image that may lead to arbitrary code execution. Apple decided to remove the code entirely instead of patching it. It has a Common Vulnerability Scoring System (CVSS) score of 7.3

Moreover, the September update also fixed other notable CVEs, including:

  • CVE-2026-65409 is a type-confusion issue in the iOS Foundation framework that could be abused for a Distributed Denial-of-Service (DDoS) attack. 
  • CVE-2026-43692 (CVSS, 8.8) and CVE-2026-64790 are validation issues in the Common Unix Printing System (CUPS) that could be exploited by a remote user to terminate the application or execute malicious code and gain elevated privileges.
  • CVE-2026-65406 is a logic-issue flaw due to improper validation that could be abused by threat actors to access sensitive user data. It is triggered through Apple’s Background Assets, which lets the user download large files and content in the background before opening an application.
Common Unix Printing System (CUPS) is an open-source print management tool for macOS and Linux that handles print queues and network communications between the printer and the operating system

Apple users are advised to update their devices by opening Settings, tapping General, and selecting Software Update.

The Importance of Keeping Your Devices Updated

PSA Intelligence emphasizes the importance of keeping software and devices up to date with the latest security patches, as these close the specific software vulnerabilities required to trigger exploits. While patching does not completely prevent undiscovered vulnerabilities, timely patch management prevents attacks that target known, unpatched gaps in a system or device. Delaying updates expands the window of vulnerabilities, giving threat actors a way to exploit security flaws. 

While updating to the latest iOS version is often recommended to patch vulnerabilities, Apple simultaneously releases alternative updates (in this case, iOS 26.7) which provides critical security patches for known vulnerabilities. This ensures that users have a secure option if upgrading to the latest major release is not possible due to aging hardware or compatibility issues with in-house enterprise apps. 

PSA Intelligence highlights the importance of consulting the US Cybersecurity and Infrastructure Security Agency (CISA) for its Known Exploited Vulnerabilities (KEV) catalog. Clients are advised to monitor for follow-on advisories reclassifying any of this release's flaws as actively exploited. 

Cybersecurity Vulnerabilties

Microsoft’s Monthly Patch - September 2026: 966 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft released its September 2026 update, which delivers fixes for 966 vulnerabilities and addresses two zero-day vulnerabilities.

The highlights of the patch include:

Addressing two actively exploited zero-days. The first is a Windows Update Stack Elevation of Privilege Vulnerability, identified as Common Vulnerabilities and Exposures (CVE) 2026-81963, which involves improper link resolution and allows a threat actor to elevate privileges locally to gain SYSTEM privileges. The second is a Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability (CVE-2026-85880). This stems from a heap-based buffer overflow that also enables an authorized threat actor to elevate privileges locally to SYSTEM.

Addressing 105 "Critical" vulnerabilities. These critical vulnerabilities include 81 remote code execution (RCE) flaws, 20 elevation of privilege flaws, 2 information disclosures, and 1 security feature bypass. Overall, the 966 flaws consist of 438 elevation of privilege, 258 RCE, 173 information disclosure, 56 denial of service, 19 security feature bypass, and 16 spoofing vulnerabilities. 

Several vendors, including Adobe, Cisco, ConnectWise, CrowdStrike, Google, Hewlett Packard Enterprise (HPE), MicroTik, N-able, Plex, SAP and SonicWall, have also released important security updates in September 2026. 

Administrators are advised to prioritize applying patches to vulnerable instances.

The list of all vulnerabilities patched for the September 2026 update can be found here.

Subscribe to CyberSecurity.PH

Subscribe to receive our latest updates as they get released.
[email protected]
Subscribe