Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Insider threats cited alongside external attacks in terms of severity:...
How are people in 15 countries leveraging AI for travel planning?
North America financial institutions lead surge in financial regulator...
Resilience the true benchmark for smart infrastructure
Vast foreign-run cybercrime networks taken down in Africa
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Resilience the true benchmark for smart infrastructure

      Resilience the true benchmark for smart infrastructure

      Wednesday, August 27, 2025, 8:21 PM Asia/Singapore | Features, IoT Security
    • Featured

      Deepfake a crisis of trust, not just technology

      Deepfake a crisis of trust, not just technology

      Tuesday, August 19, 2025, 10:06 AM Asia/Singapore | Features
    • Featured

      When talking sense into AI power mongers fails, talk $$$: A message from AI

      When talking sense into AI power mongers fails, talk $$$: A message from AI

      Thursday, August 14, 2025, 12:26 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • Awards 2025
  • Directory
  • E-Learning

Select Page

News

Will governments assert stronger oversight over tech giants deemed as global critical infrastructure?

By CybersecAsia editors | Thursday, July 24, 2025, 3:26 PM Asia/Singapore

Will governments assert stronger oversight over tech giants deemed as global critical infrastructure?

The latest CVE-2025-53770 incident, with a critical risk of 9.8, could be a signal for some compulsory introduction of governmental supervision.

On July 18, 2025, cybersecurity researchers identified and reported a widespread exploitation campaign targeting a critical Zero Day vulnerability in Microsoft SharePoint’s on-premises server software.

The flaw, named as CVE-2025-53770 (9.8 criticality), had allowed attackers to gain unauthorized, remote code execution access without login credentials, ultimately paving the way for digital key theft and deeper infiltration of compromised systems.

According to multiple security firms, the campaign intensified on 18 July and 19 July, affecting government, telecommunications, energy, and software companies globally. Initial exploits had surfaced in Western government and private sector systems but those had quickly expanded.

Attackers leveraged custom web shells to extract and print sensitive cryptographic. The theft of these keys had enabled attackers to forge authentication tokens and potentially bypass post-patch protections:

According to researchers at Eye Security: “Once inside, they’re exfiltrating sensitive data, deploying persistent backdoors, and stealing cryptographic keys.” Threat analysts from Kaspersky have commented: “The vulnerability might still be exploitable even after patching unless organizations take extra steps like rotating cryptographic keys.”

Reports suggest the campaign had compromised as many as 100 organizations by the weekend following discovery, including several US federal agencies, universities, energy firms, and at least one telecommunications provider in Asia. Microsoft has been notified, and the firm has acknowledged the gravity of the flaw. As emergency patches are rolled out for newer SharePoint editions, the firm is facing criticism for an earlier incomplete fix, as attackers reportedly exploited a previously patched but still vulnerable component.

The US Cybersecurity and Infrastructure Security Agency has issued urgent guidance recommending that potential victims disconnect internet-facing servers, rotate digital keys, and remain vigilant for further attacks. Even a US congressional hearing last year to evaluate Microsoft’s cybersecurity failures has not stopped the current vulnerability from surfacing. The firm’s autonomous stewardship over the world’s computing infrastructure management may require more governmental intervention, according to past reports.

Share:

PreviousAs cybersecurity threats to critical infrastructure escalate, US Congress reexamines Stuxnet legacy
NextPT Kereta Api Indonesia announces nationwide email and communication overhaul

Related Posts

Here is one firm’s snapshot of ransomware trends for September

Here is one firm’s snapshot of ransomware trends for September

Monday, November 4, 2024

Cybercriminals have been no NICER to the world this year

Cybercriminals have been no NICER to the world this year

Friday, July 24, 2020

Tech Week Singapore: Must-attend summits for Asia’s business and security leaders

Tech Week Singapore: Must-attend summits for Asia’s business and security leaders

Tuesday, April 4, 2023

Exposed: the hacktivist who defaced websites in 40+ countries

Exposed: the hacktivist who defaced websites in 40+ countries

Tuesday, June 2, 2020

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • 2024 Insider Threat Report: Trends, Challenges, and Solutions

    2024 Insider Threat Report: Trends, Challenges, and Solutions

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    The future of cybersecurity is a perfect storm: AI-driven attacks, cloud expansion, and the convergence …Download Whitepaper
  • Data Management in the Age of Cloud and AI

    Data Management in the Age of Cloud and AI

    In today’s Asia Pacific business environment, organizations are leaning on hybrid multi-cloud infrastructures and advanced …Download Whitepaper
  • Mitigating Ransomware Risks with GRC Automation

    Mitigating Ransomware Risks with GRC Automation

    In today’s landscape, ransomware attacks pose significant threats to organizations of all sizes, with increasing …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • CISOs can navigate emerging risks from autonomous AI with a new security framework

    CISOs can navigate emerging risks from autonomous AI with a new security framework

    See how security leaders can adopt layered strategies addressing intent, governance, and oversight to manage …Read more
  • MoneyMe strengthens fraud prevention and credit decisioning

    MoneyMe strengthens fraud prevention and credit decisioning

    Australian fintech strengthens risk management with SEON to scale lending operations securely and efficiently.Read more
  • PT Kereta Api Indonesia announces nationwide email and communication overhaul

    PT Kereta Api Indonesia announces nationwide email and communication overhaul

    The state railway operator’s upgraded email system improves privacy, operational reliability, and regulatory alignment for …Read more
  • Operationalizing sustainability in cybersecurity: Group-IB’s approach

    Operationalizing sustainability in cybersecurity: Group-IB’s approach

    See how the firm turned malware-group takedowns into measurements of sustainability and resilience gains: by …Read more

Bottom sidebar

  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2025 CybersecAsia All Rights Reserved.