
Here are some weekly APAC cybersecurity snippets that you might find interesting.
The Australian Federal Police and the FBI have arrested two members of the Perth-based TeamPCP syndicate in relation to an alleged global open-source software supply chain attack that compromised more than 1,000 organizations and stole more than 500,000 corporate credentials. The attackers secretly backdoored popular developer packages used by many people, using a backdoor that bypasses perimeter controls to steal sensitive authentication tokens and exfiltrate hundreds of gigabytes of proprietary data. This event highlights the risk of enterprise-wide compromise in a short amount of time due to third-party dependencies and the downstream businesses that are vulnerable to extended periods of unauthorized access. This holistic defense requires organizations to go beyond implicit trust in open-source libraries by enforcing rigorous software bill of materials (SBOM) validation, deploying continuous code runtime inspection, and implementing zero-trust identity architectures that prevent single credential exposures from opening up internal network privileges.
The Personal Information Protection Commission levied fines on some of the country’s biggest consumer platforms, including retail giant GS Retail and dating platform operator nRiZE, over serious authentication flaws and late reporting of breaches. Security assessments have identified security flaws in identity verification workflows that allow malicious actors to brute force authentication portals and exfiltrate detailed personal profiles, biometric attributes, and transaction logs across millions of registered accounts due to the absence of automated rate-limiting policies. Poor credential protection is a direct risk to privacy and exposes users to targeted extortion and financial fraud. To reduce these exposures, enterprises need to modernize authentication architectures with adaptive, multi-factor verification, deploy automated bot mitigations on all identity endpoints, and centralize privileged access governance under active monitoring to ensure strict compliance with data protection mandates.
National threat monitoring shows a massive increase in automated social engineering schemes targeting enterprises across Southeast Asia, with regional intelligence tracking more than 16,600 phishing operations and 19.2 million stolen credentials in the latest campaign. Threat actors are increasingly using generative tools to craft hyper-personalized voice phishing, fake banking portals and malicious payloads to trick internal personnel and steal one-time verification tokens. These trade-offs enable rapid lateral movement and massive-scale data exfiltration across financial, public, and logistics infrastructure. To withstand these dynamic campaigns, organizations need to move from static password defenses to end-to-end phishing-resistant authentication standards, embed real-time agentic threat correlation within Security Operations Centers (SOCs), and maintain immutable encrypted offsite backups to deny extortion leverage.
The Office of the Privacy Commissioner for Personal Data (PCPD) has completed a regulatory investigation into a supply chain breach of an online learning platform, Canvas, affecting the personal records and access identifiers of more than 153,000 university students and faculty. Before remediation, attackers exploited a hyper-elevated cross-site vulnerability and support access vectors on the cloud service provider to allow unauthorized actors to scrape user account information and deface institutional login portals. The event demonstrates that even with a corporate internal perimeter, integrations with cloud services are still high-value vectors for downstream identity harvest. It is important to mandate phishing-resistant MFA for all third-party software integrations, with an ongoing auditing of vendor privileges, and to safeguard institutional ecosystems by reducing the storage of personally identifiable information in external software environments.
###

Dr Seamus Phan is head of content at Microwire.news (aka microwire.info), a content outreach and amplification platform for news, events, brief product and service reviews, commentaries, and analyses in the relevant industries. Part of McGallen & Bolden Group initiative. Copyrights belong to the respective authors/owners and the service is not responsible for the content presented.
