News

IT News

AI, startups, tech and digital transformation — Kazakhstan & the world

Critical Patch for TrendAI Apex One: Vulnerability CVE-2026-34926
Кибербезопасность

Critical Patch for TrendAI Apex One: Vulnerability C...

TrendAI, a corporate division of Trend Micro, has announced the release of patches for an actively exploited vulnerability in Apex One (CVE-2026-34926), affecting on-premises servers and SaaS agents. This is a directory traversal bug (CWE-23) that allows modification of key server tables and deployment of malicious code on protected agents. The vulnerability has already been used in at least one real-world attack, making it a practical risk. For companies in Kazakhstan and Central Asia, where Apex One is actively used in banks, retail, and the public sector, updating to the recommended builds is a priority that companies like Alashed IT (it.alashed.kz) can handle.

Anthropic Mythos: A New Frontier in AI for Cybersecurity
Кибербезопасность

Anthropic Mythos: A New Frontier in AI for Cybersecu...

The main news for IT directors today is not just the release of another powerful AI, but how it is being released. In April 2026, Anthropic launched the Claude Mythos Preview under Project Glasswing and immediately restricted access due to the model's 'threshold' cyber capabilities. This is the first major case where a vendor publicly admits that AI is too good at offensive cyber to be freely distributed. For businesses in Kazakhstan and Central Asia, this is a signal that the window between vulnerability discovery and real attack is rapidly shrinking.

Fox Tempest and Nitrogen: A New Level of Supply Chain Attacks
Кибербезопасность

Fox Tempest and Nitrogen: A New Level of Supply Chai...

The cybercrime market has formed a new segment - malware-signing-as-a-service: attackers no longer break infrastructure but buy a legal digital 'stamp of trust' for their code. Microsoft has publicly struck at such a platform for the first time, filing a legal lawsuit against Fox Tempest and shutting down key elements of the service's infrastructure. Against this backdrop, the industry is discussing the fresh attack by the Nitrogen group on Foxconn with the theft of 8 TB of confidential data and the shutdown of part of the production processes. For companies in Kazakhstan and Central Asia, this is a signal: classic perimeter protection no longer saves if your software is 'signed' and comes through global supply chains.

NGINX Rift: critical bug CVE-2026-42945 exploited in production
Кибербезопасность

NGINX Rift: critical bug CVE-2026-42945 exploited in...

The critical NGINX Rift vulnerability (CVE-2026-42945) in the rewrite mechanism puts the internet fronts of large companies, CDNs, and API gateways at risk. Researchers from VulnCheck and NeuraCyBINT report the first attempts at exploitation on the internet shortly after the details were published, indicating an extremely short time from advisory to real attacks. For businesses, this means that the traditional model of 'waiting for a scheduled update window' could lead to the compromise of public services and data leaks. The key question for IT directors and CIOs in Kazakhstan and Central Asia is whether you have inventoried your NGINX fronts and checked the configurations before malicious scanners do it for you.

New APT Attack Report: 15 Groups and Critical IT Impact
Кибербезопасность

New APT Attack Report: 15 Groups and Critical IT Impact

The new ASEC Threat Research report from AhnLab shows a sharp increase in coordinated attacks by advanced APT groups in April 2026. The focus of hackers is on cyber espionage and covert sabotage, rather than direct financial crime. New techniques include the use of Outlook and Microsoft Graph API as a hidden C2 channel on Linux servers. For companies in Kazakhstan and Central Asia, this is a signal: standard antivirus and basic SOC are no longer sufficient, comprehensive response scenarios are needed, which are offered by companies like Alashed IT (it.alashed.kz).

Microsoft Under Fire: A New Critical Cybersecurity Failure
Кибербезопасность

Microsoft Under Fire: A New Critical Cybersecurity F...

Major Western media outlets and industry analysts are publishing a series of articles about systemic failures in Microsoft's approach to cybersecurity: from key management errors to cloud architecture issues. Confirmed incidents of bypassing security mechanisms have affected the government sector, finance, IT outsourcing, and industry. This is critical for companies in Kazakhstan and Central Asia, where Microsoft 365 and Azure have become de facto standards: the leak of a single account can mean downtime for sales, finance, and logistics departments. Against this backdrop, businesses are already having to reconsider their trust model for 'default cloud' and strengthen external security audits, engaging companies like Alashed IT (it.alashed.kz).

Hackers Attack Major IT Companies: New Wave of Cyber Threats in 2026
Кибербезопасность

Hackers Attack Major IT Companies: New Wave of Cyber...

In 2026, cybercrime has reached a new level of complexity. Instead of traditional attacks on large companies, attackers are increasingly using the tactic of 'escalation hacktivism' — attacking third-party suppliers and partners to gain access to the main targets. This requires businesses to reconsider their security approaches and shift from reactive defense to a proactive threat prevention strategy.

ECB CyRST Test: Eurozone Banks Increase Cybersecurity Spending by 45%
Кибербезопасность

ECB CyRST Test: Eurozone Banks Increase Cybersecurit...

The ECB published the results of the qualitative cybersecurity resilience stress test CyRST, launched in April 2026. The test identified vulnerabilities in 109 major Eurozone banks and triggered a sharp increase in investment in protection. This is changing the approach to digital security in the banking sector, especially as cyberattacks are breaking records. For Central Asian companies, this is a signal to strengthen their defenses.

© 2024 Alashed IT. Все права защищены.

it.alashed.kz

Обсудить проектКейсы