Cybersecurity Monthly Report (July 2026)
Cybersecurity Monthly Report (July 2026)
1. Cybersecurity: Long Story Short
1.1 "Harvest Now, Decrypt Later" Exposes Confidential Information to Quantum Risks
Although the deadline for Post-Quantum Cryptography (PQC) migration may sound distant, imagine the financial transactions, sensitive personal data, or corporate secrets you transmit over the internet today. While protected by existing encryption technologies, hackers are very likely quietly intercepting and storing this data, waiting to instantly decrypt it once large-scale quantum computing technology matures in the future. This attack model, known as "Harvest Now, Decrypt Later," has gradually become a major real-world cybersecurity threat. Quantum computing expert Michele Mosca proposed a simple formula: "The required security duration of confidential information (X)" plus "the time required to upgrade systems to post-quantum encryption (Y)". If the sum of these two durations is longer than "the time required to develop a large-scale general-purpose quantum computer (Z)"—that is, X + Y > Z—it means your confidential information could be cracked by quantum computers before its confidentiality period expires. Based on past experience, completely replacing specific types of cryptographic systems can be time-consuming; therefore, it is best to plan early to cope with the impending quantum risks.
1.2 International Trends: Analyzing U.S. Post-Quantum Policy
On June 22, 2026, the United States issued Executive Order titled "Securing the Nation Against Advanced Cryptographic Attacks" (Note 1), aiming to transition federal information systems to PQC and assist critical infrastructure providers in completing their migration to safeguard national security. The executive order focuses on "coordinating policy planning, technical guidance assistance, and revising procurement regulations," and proposes several specific actions with deadlines:
(1) Establish Lead Officials and Issue Guidance for Inventorying High Value Assets (Within 30 and 90 Days): Each agency must establish a "PQC Migration Lead" within 30 days. The Office of Management and Budget (OMB) shall issue guidance within 90 days requiring agencies to inventory their High Value Assets (HVA) and High Impact Systems (excluding National Security Systems) (Notes 2, 3), and develop and submit corresponding implementation plans.
(2) Launch PQC Migration Pilot Programs and Accelerate Validation Processes (Within 180 Days): The National Institute of Standards and Technology (NIST) shall initiate PQC migration pilot programs for specific information systems owned or operated by NIST, expected to be completed by the end of 2027. The Department of Commerce shall revise the processes used by the Cryptographic Module Validation Program (CMVP) to accelerate cryptographic module validation.
(3) Issue Guidance on Baseline Elements of Cryptographic Bill of Materials (Within 270 Days): The Department of Homeland Security (DHS) shall issue public guidance specifying the baseline elements that a Cryptographic Bill of Materials (CBOM) must contain, ensuring that cryptographic assets used in software and hardware components can be automatically evaluated in the future.
(4) Revise Procurement Regulations and Strengthen Vulnerability Disclosure Requirements (Within 180 and 270 Days): The Federal Acquisition Regulatory Council shall issue draft Federal Acquisition Regulation (FAR) rules within 180 days, requiring covered contractors to comply with PQC algorithm standards by December 31, 2030. Additionally, draft Vulnerability Disclosure Program rules shall be revised within 270 days to ensure contractors implement NIST-guided Vulnerability Disclosure Policies (VDPs), including disclosing cryptographic weaknesses and the use of non-FIPS-approved algorithms.
(5) Clearly Define Migration Deadlines (Medium- and Long-Term Goals): All HVAs and High Impact Systems across agencies are required to fully migrate to PQC technology, implementing "Key establishment" by December 31, 2030, and "Digital signatures" by December 31, 2031.
(6) Assist Critical Infrastructure Providers in Developing PQC Migration Plans: Each Sector Risk Management Agency (SRMA) (Note 4) shall collaborate with DHS to assist critical infrastructure owners and operators in formulating PQC migration plans.
1.3 Policy Planning of Government Agencies in Taiwan
From the latest U.S. Executive Order, it is clear that facing the "Harvest Now, Decrypt Later" quantum risk, the U.S. is using time-bound concrete measures to accelerate PQC migration across federal agencies and supply chains. Taiwan has also taken early action. For example, the Administration for Digital Industries (ADI) of MODA, together with the "PQC Cybersecurity Industry Alliance," released the Post-Quantum Cryptography Migration Guidelines in 2025, uniting industry, government, and academia to promote post-quantum cybersecurity R&D and application implementation.
Furthermore, the Administration for Cyber Security (ACS) of MODA has planned to issue Taiwan's Government Agency Post-Quantum Cryptography Migration Policy by the end of this year to guide overall agency migration timelines. Aligning with international standards from the U.S. and EU while monitoring global developments and emerging technologies, ACS is drafting the Post-Quantum Cryptography Migration Practical Reference Manual to provide execution paths and transitional reinforcement mechanisms for agencies.
1.4 Recommendations for CISOs
The latest U.S. policy dynamics demonstrate that PQC migration is not a future issue, but an ongoing reality critical to cybersecurity. To guide agencies in steadily promoting PQC migration and seamlessly aligning with the implementation of Taiwan's future PQC policy, CISOs are advised to draw from U.S. strategies and proactively undertake the following three preparatory measures:
(1) Inventory Sensitive Information and Cryptographic Assets: Perform a comprehensive inventory of the "confidentiality duration" of sensitive data. Map data production, transmission, and storage paths to corresponding information systems, devices, software, certificates, Public Key Infrastructure (PKI), network protocols, and third-party services. Identify encryption algorithms used to establish a cryptographic asset inventory and prioritize subsequent PQC migration tasks.
(2) Introduce Crypto-Agility into Systems: Incorporate modular "Crypto-agility" designs during the system design and development stages to ensure flexibility when changing encryption mechanisms, facilitating future PQC migration.
(3) Add Vulnerability Disclosure Requirements to Outsourcing Contracts: Before systems possess quantum-resistant capabilities, contract terms should require vendors to proactively disclose cryptographic weaknesses to identify algorithms vulnerable to quantum attacks.
Facing the quantum threat of "Harvest Now, Decrypt Later," cybersecurity defense systems worldwide are encountering an unprecedented challenge, which also presents a transformation opportunity for Taiwan to build "digital trust" and reliable supply chains. However, PQC migration is a systemic project spanning technology, business processes, and organizational governance. Only by planning early and implementing migration step-by-step can we secure an advantage in the quantum defense war.
Footnotes:
- Note 1: The White House. (2026, June 22). Securing the nation against advanced cryptographic attacks.
- Note 2: "High Value Asset" (HVA) refers to federal information or systems designated as HVAs pursuant to OMB Memorandum M-19-03, Enhancing the Cybersecurity of Federal Information and Information Systems Through the High Value Asset Program, or any successor document.
- Note 3: "High Impact System" refers to an information system in which at least one security objective (confidentiality, integrity, or availability) is rated as having a "High" potential impact value under FIPS 199 (Standards for Security Categorization of Federal Information and Information Systems).
- Note 4: Sector Risk Management Agencies are pursuant to National Security Memorandum No.22 (April 30, 2024), Critical Infrastructure Security and Resilience, or successor documents.
2. Recent Policy Highlights
Release of the Action Guidelines for Cyber Incident Response to Assist Enterprises in Handling Cyber Threats:
On July 31, the Administration for Cyber Security (ACS) under MODA published the Action Guidelines for Cyber Incident Response. The document covers four core stages—Preparation, Detection & Response, Reporting & External Communication, and Recovery & Continuous Improvement—along with checklists. It provides standard operation procedures (SOPs) for six common scenarios: device infection, account compromise, phishing, business payment fraud, ransomware, and DDoS attacks, assisting non-technical enterprise staff in taking damage control measures to mitigate financial and operational impacts.
3. Recent Cybersecurity Incident Sharing
Failure in Website Authentication Mechanisms Triggers Severe Cybersecurity Incident
A recent incident revealed severe flaws in password reset and One-Time Password (OTP) validation mechanisms on an agency website, allowing attackers to bypass Two-Factor Authentication (2FA) and reset passwords. In the first vector, the website allowed password resets via email verification codes; however, the verification code was exposed in plaintext within the web page source code. Once attackers obtained a user's email address, they could retrieve the verification code directly from the source code without accessing the victim's email inbox, allowing them to reset the password. In the second vector, attackers identified the administrator's email and intercepted HTTP request packets to discover the password reset path. They were able to access the password reset page directly without prior authentication. After logging in with the new password, the system failed to deliver the OTP through an out-of-band channel to the legitimate user; instead, it returned the OTP directly in the browser's HTTP response packet. Attackers extracted the OTP from the response payload, bypassed the secondary authentication step, and successfully logged into the admin dashboard, as shown in Figure 1.



Figure 1: Failure of authentication
Lessons Learned
Although security mechanisms such as email verification codes, password resets, and OTPs were deployed, sensitive validation data was exposed on the front end, and the back end failed to verify user identity throughout the reset workflow. Consequently, controls were bypassed sequentially. The following measures should be implemented:
(1) Strengthen Password Reset Workflow Verification: Reset tokens or verification codes must be generated using cryptographically secure random algorithms and enforce three properties: time-limited, single-use, and bound to the specific account. Expiration windows and single-use limits must be strictly enforced. Servers must validate credentials before permitting password updates to prevent unauthorized access via direct URL manipulation.
(2) Prevent Exposure of Sensitive Verification Data on Front-End Interfaces: Email verification codes and OTPs must never be exposed in source code, hidden fields, or server response payloads. Front-end components should only capture user inputs, while credential verification must be executed strictly on the server or through trusted authentication services. Full access permissions must not be granted before completing OTP verification.
(3) Revoke Existing Access Sessions Upon Password Reset: Upon completing a password reset, immediately invalidate reset tokens and terminate all active login sessions. Force users to undergo standard authentication using the new password and OTP. Avoid automatically creating authenticated sessions post-reset to prevent this feature from being used to bypass login authentication. In addition, immediately notify account owners via secondary channels to facilitate early detection of unauthorized modifications.
Reference: Regulations Governing the Classification of Cyber Security Responsibility Levels – Appendix 10 – Security Baselines for Information and Communication Systems– “Access Control” and “System and Information Integrity”.
4. Cybersecurity Trends
4.1 National Government Cybersecurity Threat Trends
Ex ante joint defense and monitoring
This month, a total of 73,650 cybersecurity joint defense intelligence items were collected from government agencies (a decrease of 16,464 items compared to the previous month). Among identifiable threat categories, information collection ranked first (54%), primarily involving the acquisition of information through techniques such as scanning, probing, and social engineering. This was followed by intrusion attempts (21%), mainly involving attempts to access unauthorized hosts, and intrusion attacks (9%), most of which involved unauthorized system access or the acquisition of system or user privileges. The distribution of intelligence volume over the past year is shown in Figure 2.



Figure 2: Statistics of cybersecurity monitoring intelligence in joint defense
Hackers are stealing sensitive host information via malicious emails
In-depth threat intelligence analysis indicates that attackers have recently distributed LxBase RAT via malicious emails to exfiltrate sensitive data. LxBase RAT is an info-stealing Remote Access Trojan that targets browser stored credentials, digital wallets, and social media accounts. It incorporates sophisticated anti-detection and evasion techniques, gathers local system data, and can download secondary malware payloads. Defensive recommendations have been distributed to all monitored agencies.
In-process reporting and responding
A total of 145 cybersecurity incidents were reported this month (including 62 exercise reports), representing 0.62 times the volume compared to the same period last year. Unlawful intrusions accounted for the majority at 62.07% of reported incidents.
This month, attackers were observed utilizing open-source AI Agents (such as OpenClaw and Hermes Agent) to launch automated attacks against government web assets. Reported impacts included cloud service breaches leading to data leaks, as well as exploitation of existing vulnerabilities on individual websites, such as SQL Injection, Path Traversal, and Arbitrary File Download.
Detailed statistics on cybersecurity incident notifications over the past year are shown in Figure 3.



Figure 3: Statistics of cybersecurity incident reports
4.2 Important Vulnerability Alerts: Please refer to Appendix for more details
5. International Cybersecurity News
“GhostApproval” Technique Leads AI Coding Tools to Alter Files Outside of Sandbox
Source: SC Media
Wiz reported that a technique dubbed “GhostApproval” could enable attackers to trick AI coding assistants into editing files outside their intended workspaces, posing a risk to user systems. The proof-of-concept of the technique abused symlinks using README files that instructed the AI to edit a file within the repo, which was actually a symlink stealthily pointing to a critical file on the victim’s machine outside of the sandbox. Through this, attackers can write a malicious SSH key to the victim’s system settings (e.g., ~/.ssh/authorized_keys), thereby directly gaining system access.
Six AI coding assistants—Amazon Q Developer, Anthropic Claude Code, Augment Code, Cursor, Google Antigravity and Windsurf—were tested, and all were found vulnerable. At the time of reporting, AWS, Anthropic, Cursor and Google had issued patches for the flaw, while Windsurf's response was still pending, and Augment Code did not consider GhostApproval to be a vulnerability. Relevant vendors advised users to update their software to the latest version as soon as possible, or confirm that automatic fixes have been applied, to ensure security.
Critical ServiceNow Code Execution Flaw Now Exploited in Attacks
Source: Bleeping Computer
Threat intelligence company Defused reported active exploitation of a critical vulnerability CVE-2026-6875 in the widely used ServiceNow AI Platform, beginning July 19. The vulnerability, discovered by Searchlight Cyber on April 1, allowed unauthenticated attackers to escape the sandbox and execute code remotely within the platform. Attackers are targeting the same pre-auth sink documented in the original proof-of-concept but using a different technique.
Given ServiceNow’s widespread adoption among Fortune 500 companies, this flaw enables high-complexity attacks that could compromise core enterprise workflows and potentially impact sensitive business data. Although ServiceNow has not yet flagged the flaw as actively exploited in its official advisory, the actual risk cannot be overlooked. ServiceNow released patches for hosted instances in April and for self-hosted instances on July 13, advising all customers to upgrade to the latest version immediately to prevent core enterprise data from being compromised.
Appendix: Major Vulnerability Alerts
| Alert Type | Category | Description |
|---|---|---|
| Vulnerability Alert |
Web Server Apache HTTP Server Severity: CVE-2026-23918 (CVSS 8.8) CVE-2026-29167 (CVSS 9.8) CVE-2026-44631 (CVSS 9.8) |
• Memory double free, use-after-free, and buffer underflow vulnerabilities identified in Apache HTTP Server. • In the worst-case scenario, a remote attacker could execute arbitrary code. Affects versions 2.4.0 through 2.4.67. |
|
Virtualization Platforms VMware ESX, vCenter, Workstation & Fusion Severity: CVE-2026-59309 (CVSS 9.8) CVE-2026-59310 (CVSS 9.8) CVE-2026-47876 (CVSS 9.3) |
• Multiple critical security flaws were found in VMware ESX, vCenter, Workstation, and Fusion, affecting government and enterprise virtualization infrastructure. • Unauthenticated attackers with network access to vCenter can bypass authentication or execute arbitrary code on vCenter. Local VM admin privileges may allow code execution on the ESX host via VMXNET3. • Apply official vendor patches for affected VMware products. |
|
|
Data Collection and Analytics Platform Splunk Enterprise, Splunk Cloud Platform & Splunk Secure Gateway Severity: CVE-2026-20251 (CVSS 8.8) |
• Insecure deserialization flaw in the Splunk Secure Gateway App. • Low-privileged users (without admin/power roles) can use specially crafted data in the App Key Value Store to construct arbitrary Python objects and execute code. |
|
| Known Exploited Vulnerabilities |
Secure Access Gateway SonicWall SMA1000 Series Severity: CVE-2026-15409 (CVSS 10.0) |
• Added to CISA KEV in July 2026. Active exploitation confirmed by SonicWall. • Server-Side Request Forgery (SSRF) flaw in SMA1000 Appliance Workplace interface allows unauthenticated remote attackers to send unauthorized requests. • Update firmware to versions 12.4.3-03453, 12.5.0-02835, or higher. |
|
Collaboration and Document Platform Microsoft Office SharePoint Severity: CVE-2026-50522 (CVSS 9.8) |
• Added to CISA KEV in July 2026 due to active exploitation. • Microsoft Office SharePoint contains an insecure deserialization vulnerability, which allows unauthenticated remote attackers to execute arbitrary code over the network." |
|
|
Enterprise Communications and Collaboration Platform Cisco Unified Communications Manager (CUCM) & Unified CM SME Severity: CVE-2026-20230 (CVSS 8.6) |
• Added to CISA KEV on June 25 with active exploitation confirmed. Cisco confirmed active exploitation in a July 1 advisory update. • When WebDialer is enabled, unauthenticated remote attackers can issue crafted HTTP requests to perform SSRF, write system files, and escalate privileges to root. |
|
| Known Exploited Vulnerabilities |
Security Management System Check Point Security Management Server & Multi-Domain Security Management Server Severity: CVE-2026-16232 (CVSS 9.1) |
• Added to CISA KEV following observed in-the-wild exploitation. • Unauthenticated remote attackers can acquire application login tokens and authenticate via SmartConsole with full admin privileges to modify security policies and system configurations. |
Alert Explanation:
"Vulnerability Alert": This is a verified vulnerability that has not yet been widely exploited by attackers. It is recommended to patch the vulnerability as soon as possible.
"Known Exploited Vulnerabilities": Successful attacks using this vulnerability are known. It is recommended to immediately evaluate and patch it.