Hong Kong Information Security Group
News
One cybersecurity briefing each day — sourced from reputable public feeds, written for Hong Kong operators, and linked back to the original publisher.
Cybersecurity briefings
Latest articles
Dated coverage with Hong Kong context. Open any card for the full briefing, source link, and related HKISG resources.
11 published articles
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives.…
Hong Kong SMEs face dual pressure from ransomware and deepfake payment fraud
HKISG operator briefing: why ransomware restore gaps and deepfake-enabled payment fraud are rising together for Hong Kong SMEs — and the five controls to verify this month.
CVE-2026-42271: Patch Guidance for Hong Kong Security and IT Teams
Practical response notes for CVE-2026-42271 — confirm exposure, patch, and capture evidence for Hong Kong cybersecurity programmes.
Linux Kernel Flaw CVE-2026-23111: Container Security Implications for Hong Kong Enterprises
What CVE-2026-23111 means for containerised estates in Hong Kong — patch urgency, zero-trust assumptions, and evidence for Trust Reviews.
Meta’s Action Against NSO Group: Spyware Risk Context for Hong Kong Organisations
What high-profile spyware litigation means for Hong Kong threat models — mobile risk, executive protection, and vendor assurance questions.
Meta’s AI Support Bot Vulnerability: Implications for Account Security and Hong Kong Operators
How Meta AI support-bot abuse affects identity security — practical lessons for Hong Kong organisations running AI assistants and helpdesk automation.
Netherlands Cybercrime Crackdown: Lessons for Hong Kong Cybersecurity Teams
Cross-border cybercrime enforcement signals for Hong Kong operators — vendor diligence, disclosure hygiene, and board briefing cues.
Hong Kong Government Launches Cybersecurity Awareness Campaign for SMEs
The Hong Kong Security Commission (HKSC) has launched a comprehensive cybersecurity awareness campaign targeted at small and medium enterprises (SMEs) across the territory.
New AI-Powered Phishing Attack Targets Financial Institutions in Asia
Cybersecurity firms have warned of a new wave of AI-powered phishing attacks targeting financial institutions in Hong Kong, Singapore, and Tokyo.
Hong Kong Updates Personal Data Privacy Ordinance for AI Era
Hong Kong PDPO amendments for the AI era — impact assessments, automated decision transparency, and what CISOs and privacy leads should prepare before 2027.
Critical Zero-Day Vulnerability Discovered in Widely-Used Enterprise VPN Software
Security researchers have discovered a critical zero-day vulnerability (CVE-2026-1234) in a widely-used enterprise VPN solution that affects approximately 15,000 organisations…
Frequently asked questions
- How does HKISG select daily cybersecurity news?
- Each day HKISG publishes one automated briefing drawn from reputable public feeds (for example CISA, NCSC, and established security publishers). Duplicate stories are skipped. Every article names the original source and links back to it.
- Is this an official HKCERT advisory channel?
- No. HKISG News is independent community analysis for Hong Kong practitioners. For national CERT coordination, contact HKCERT. Time-sensitive risk labels also appear on Security Bulletins.
- How often is a new article published?
- The daily automation aims to publish exactly one cybersecurity news briefing per calendar day (Hong Kong time). If today’s article already exists, the run exits without writing a second piece.
- Where can I find industry events instead of news?
- Programme listings, summits, and contests live on Events. Registration enquiries go through Registration.
