Hong Kong Information Security Group
News
One cybersecurity briefing each day — sourced from reputable public feeds, written for Hong Kong operators, and linked back to the original publisher.
Cybersecurity briefings
Latest articles
HKISGCounterfeit installers to system compromise: Tracking a deceptive software download campaign
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives.…
HKISGHong Kong SMEs face dual pressure from ransomware and deepfake payment fraud
HKISG operator briefing: why ransomware restore gaps and deepfake-enabled payment fraud are rising together for Hong Kong SMEs — and the five controls to verify this month.
HKISGCVE-2026-42271: Patch Guidance for Hong Kong Security and IT Teams
Practical response notes for CVE-2026-42271 — confirm exposure, patch, and capture evidence for Hong Kong cybersecurity programmes.
HKISGLinux Kernel Flaw CVE-2026-23111: Container Security Implications for Hong Kong Enterprises
What CVE-2026-23111 means for containerised estates in Hong Kong — patch urgency, zero-trust assumptions, and evidence for Trust Reviews.
HKISGMeta’s Action Against NSO Group: Spyware Risk Context for Hong Kong Organisations
What high-profile spyware litigation means for Hong Kong threat models — mobile risk, executive protection, and vendor assurance questions.
HKISGMeta’s AI Support Bot Vulnerability: Implications for Account Security and Hong Kong Operators
How Meta AI support-bot abuse affects identity security — practical lessons for Hong Kong organisations running AI assistants and helpdesk automation.
HKISGNetherlands Cybercrime Crackdown: Lessons for Hong Kong Cybersecurity Teams
Cross-border cybercrime enforcement signals for Hong Kong operators — vendor diligence, disclosure hygiene, and board briefing cues.
HKISGHong Kong Government Launches Cybersecurity Awareness Campaign for SMEs
The Hong Kong Security Commission (HKSC) has launched a comprehensive cybersecurity awareness campaign targeted at small and medium enterprises (SMEs) across the territory.
HKISGNew AI-Powered Phishing Attack Targets Financial Institutions in Asia
Cybersecurity firms have warned of a new wave of AI-powered phishing attacks targeting financial institutions in Hong Kong, Singapore, and Tokyo.
HKISGHong Kong Updates Personal Data Privacy Ordinance for AI Era
Hong Kong PDPO amendments for the AI era — impact assessments, automated decision transparency, and what CISOs and privacy leads should prepare before 2027.
HKISGCritical Zero-Day Vulnerability Discovered in Widely-Used Enterprise VPN Software
Security researchers have discovered a critical zero-day vulnerability (CVE-2026-1234) in a widely-used enterprise VPN solution that affects approximately 15,000 organisations…
