Welcome to Cyber Briefing, your daily source for all things cybersecurity. We bring you the latest advisories, alerts, incidents, and news every weekday.
Suspected Chinese-linked activity targeting South Korean financial institutions and Taiwanese research organizations. AI-powered tools are being used to support intrusions and highly convincing phishing campaigns, while adversary-in-the-middle techniques and malicious QR codes are being used to capture credentials and MFA tokens. Separately, the Oracle Health breach has expanded to nearly 20 million affected individuals, underscoring the scale of exposure when sensitive healthcare data is compromised.
At the executive level, new warnings from Europol and the U.S. GAO put post-quantum preparation on the priority list, with some experts estimating that cryptographically relevant quantum computing could arrive within the next few years. The legal and financial risks extend beyond the original cyber incident, as an alleged ransomware recovery scheme generated $11 million by concealing ransom payments and inflating recovery fees.
Listen to our podcast here ⏬
⚡THREAT LANDSCAPE
Chinese Hacker Uses AI in South Korean Bank Campaign
A suspected Chinese threat actor used AI-powered pentesting tools to breach multiple South Korean financial institutions between late September and early October 2026, stealing data from at least 65,000 customers. CrowdStrike linked the attacks to ARTEX, an open-source AI pentesting framework, combined with multiple large language models including Claude, DeepSeek, and Grok. The attacker compromised loan inquiry systems and employee mobile platforms at banks including Shinhan Bank and Yegaram Savings Bank, then attempted to sell the stolen data through Korean Telegram channels. Read More
UAT-11985: AI-assisted AitM phishing targeting Taiwan
Cisco Talos discovered a sophisticated spear-phishing campaign (UAT-11985) targeting Taiwan research organizations using AI-generated emails that impersonated legitimate academic institutions. The attackers deployed adversary-in-the-middle (AitM) phishing infrastructure to intercept Google credentials and multi-factor authentication tokens, while also embedding malicious QR codes in event posters to expand their reach beyond email recipients. Analysis of the phishing kit’s code structure and language patterns indicates the developers likely operate in Simplified Chinese, suggesting mainland Chinese origins. Read More
🚨INCIDENTS & REAL-WORLD IMPACT Oracle Health breach affects nearly 20M
Oracle Health has disclosed a data breach affecting nearly 20 million individuals, significantly higher than initial reports suggested. The breach involved unauthorized access to patient health information stored in Oracle’s healthcare systems. Healthcare organizations using Oracle Health platforms should review their security configurations and notify affected patients according to regulatory requirements. Read More
🔓 EXECUTIVE RISK & CYBERNOMICS
Europol and US GAO Warn of Quantum Computing Threats
Europol and the US Government Accountability Office (GAO) have issued reports warning that quantum computers capable of breaking current encryption could arrive as soon as 2029, threatening government and corporate security. The GAO found that none of 24 federal agencies have fully implemented three critical post-quantum cryptography (PQC) practices: developing inventories of vulnerable systems, identifying funding needs, and testing PQC solutions. Organizations should immediately upgrade to modern protocols like TLS 1.3, enable forward secrecy, delete unnecessary sensitive data, and begin planning PQC adoption to protect against harvest now decrypt later attacks where adversaries collect encrypted data today to decrypt later. Read More
🛡️ POLICY, REGULATION & LEGAL SIGNALS
Ransomware Recovery Scheme Nets $11M Markup
Zohar Pinhasi operated a ransomware recovery scheme where he secretly paid ransoms to obtain decryption keys, then charged victims significantly inflated fees for remediation services while concealing that he had simply purchased the keys. The scheme generated an $11 million markup over the actual ransom costs. Organizations affected by ransomware should verify that recovery services are legitimate and transparent about their methods, and consider reporting suspected fraudulent recovery operations to law enforcement. Read More
💻 CAREER ENABLEMENTContext Over Alerts: SOC Evolution Strategy
Security operations centers are shifting from alert-based detection to behavioral analysis as attackers increasingly use legitimate credentials and authorized tools to evade traditional defenses. Experts argue that modern threats require understanding patterns over time rather than flagging individual suspicious events, since compromised sessions, insider threats, and AI-driven actions can all appear normal in isolation. Organizations should prioritize context-driven detection
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article:
