Cyber Command Armed Forces of the Philippines

Cyber Command Armed Forces of the Philippines One Cyber. One Command.

15/09/2026

𝐋𝐢𝐛𝐫𝐞𝐧𝐠 𝐖𝐢-𝐅𝐢, 𝐌𝐚𝐲 𝐁𝐚𝐲𝐚𝐝 𝐏𝐚𝐥𝐚?

Sanay ka bang kumonekta agad sa "Free WiFi" sa mall, airport, o café? Bago ka mag-login sa banking app o mag-check ng email sino ba talaga ang kasama mo sa network na 'yan?

May tinatawag na "Man-in-the-Middle Attack", pekeng Wi-Fi na kamukhang-kamukha ng totoong network, pero silent na nanonood ng lahat ng ginagawa mo online. Passwords, messages, kahit banking info puwedeng makita, real-time.

Hindi na kailangan pang i-hack ang phone mo. Ang Wi-Fi mismo ang siyang papasukan.

Panoorin ang video para malaman kung paano ka mananatiling ligtas sa public Wi-Fi.

Konektado ka man, may panganib namang kapalit. I-share mo ito sa katropa mo bago sila mag-log in ulit!






CYBER ALERT | CROWDSTRIKE FALCON ZERO-DAY: WHEN THE DEFENDER BECOMES THE TARGETA newly disclosed zero-day vulnerability ...
10/09/2026

CYBER ALERT | CROWDSTRIKE FALCON ZERO-DAY: WHEN THE DEFENDER BECOMES THE TARGET

A newly disclosed zero-day vulnerability dubbed FalconFlank reportedly affects CrowdStrike Falcon, a widely deployed endpoint security platform. The vulnerability involves the platform’s Microsoft Office malicious macro-removal feature and can potentially allow an attacker to escalate privileges on affected Windows systems. The proof-of-concept (PoC) was reported to work even on fully updated Windows 11 25H2 and Windows Server 2025 systems under specific Falcon configurations.

KEY FACTS

• FalconFlank is described as a privilege-escalation vulnerability affecting CrowdStrike Falcon.
• The issue involves Falcon’s Microsoft Office File Suspicious Macro Removal feature.
• The reported PoC works against fully updated Windows 11 25H2 and Windows Server 2025 systems when certain Falcon protections are enabled.
• CrowdStrike said it was actively investigating the claims and advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting.
• CrowdStrike stated that customers remain protected through its Cloud Anti-malware for Microsoft Office Files settings.
• The disclosure highlights a broader security concern: endpoint protection products themselves can become targets for exploitation.
• Other recently disclosed endpoint-security vulnerabilities reportedly affected products from Kaspersky and Gen Digital/Avast.

RED FLAGS

• Security software behaving unexpectedly or generating unusual errors.
• Attempts to modify endpoint-security policies or exclusions without authorization.
• Unexpected requests to disable antivirus or endpoint protection features.
• Unusual privilege changes or users suddenly obtaining administrator-level access.
• Suspicious Office documents accompanied by unexpected macro-related activity.
• Unexplained DLL loading, process creation, or other abnormal activity on protected endpoints.
• Security alerts that are repeatedly dismissed, excluded, or bypassed without proper validation.

RECOMMENDATIONS

• Follow CrowdStrike's latest security advisory and guidance for FalconFlank and apply vendor-provided mitigations or updates as they become available.
• Review Falcon configurations and determine whether the affected Suspicious Macro Removal Windows policy is enabled.
• Do not blindly disable endpoint-security controls; coordinate changes with authorized cybersecurity or system administrators.
• Closely monitor endpoints for unusual privilege escalation, process ex*****on, and configuration changes.
• Maintain current Windows, endpoint-security, and application updates.
• Review security logs and endpoint telemetry for suspicious activity, particularly around privileged accounts and Office document ex*****on.
• Apply the principle of least privilege so that exploitation of a local vulnerability does not automatically translate into broad administrative access.
• Treat security products as part of the attack surface and include them in vulnerability management, patch management, and security testing programs.

FalconFlank is a reminder that cybersecurity does not end with installing an endpoint protection product, security tools themselves must also be continuously monitored, updated, and tested. Defense-in-depth, rapid vulnerability response, least privilege, and continuous monitoring remain essential even when trusted security solutions are already deployed.










LOOK | CYBER COMMAND, AFP CONDUCTS PRE-ANNIVERSARY ACTIVITIES AT FIRST SCOUT RANGER REGIMENTThe Cyber Command, Armed For...
02/09/2026

LOOK | CYBER COMMAND, AFP CONDUCTS PRE-ANNIVERSARY ACTIVITIES AT FIRST SCOUT RANGER REGIMENT

The Cyber Command, Armed Forces of the Philippines (AFP), under the leadership of BGEN JOEY T. FONTIVEROS, conducted a series of pre-anniversary activities at the First Scout Ranger Regiment (FSRR) in Bulacan on 27 August 2026.

The activities include Tree-Planting, Cyber Awareness Lecture, and Fun Shoot, aimed at promoting environmental stewardship, strengthening cybersecurity awareness, and fostering camaraderie and esprit de corps among participating personnel. The tree-planting activity underscored the Command’s commitment to environmental responsibility and sustainable practices.
BGEN ERNEST JOHN C JADLOC, Commander, 202nd Infantry (Unifier) Brigade, 2nd Infantry Division, Philippine Army (2ID, PA), also participated in the tree-planting activity, joining personnel in advancing the shared commitment to environmental conservation and community responsibility.

The Cyber Awareness Lecture highlighted the importance of cyber hygiene, responsible use of information and communication technologies, and vigilance against evolving cyber threats. The lecture reinforced the principle that cybersecurity is a shared responsibility, emphasizing the vital role of every military personnel in safeguarding information, protecting digital assets, and maintaining a secure cyberspace in support of the AFP mission. The pre-anniversary activities also included a fun shoot, providing participating personnel an opportunity to strengthen teamwork, discipline, camaraderie, and esprit de corps. The activity further fostered professional relationships and cooperation among the participating units, contributing to a stronger sense of unity and partnership within the Armed Forces.

The Cyber Command, AFP extends its sincere appreciation to the First Scout Ranger Regiment, headed by BGEN MONTANO B ALMODOVAR PA, for its warm hospitality and support in hosting the activities. The successful conduct of the pre-anniversary event strengthened the partnership among the participating units and highlighted the importance of collaboration, camaraderie, and shared commitment in building a more capable and mission-ready force.

As the Cyber Command, AFP approaches its anniversary, the Command remains steadfast in its commitment to strengthening the AFP’s cyber resilience, promoting a culture of cybersecurity awareness, and contributing to a more capable, cohesive, and future-ready Armed Forces of the Philippines.




31/08/2026

CYBER ALERT | TinyRCT Backdoor Powering Cyber Espionage in Southeast Asia

Overview
Cybersecurity researchers have uncovered a sophisticated cyber espionage campaign involving a Chinese-speaking Advanced Persistent Threat (APT) group deploying a newly discovered backdoor called TinyRCT against government and state-owned energy organizations in Southeast Asia.

The malware enables attackers to remotely control compromised systems, steal sensitive files, capture screenshots, and maintain long-term access while avoiding detection. The campaign highlights the persistent threat posed by nation-state actors targeting critical infrastructure and emphasizes the importance of proactive cyber defense.

Key Facts

• Researchers attributed the activity to a Chinese-speaking threat cluster tracked as CL-STA-1062.

• The campaign primarily targets government agencies and state-owned energy organizations in Southeast Asia.

• Attackers utilize a newly identified custom backdoor named TinyRCT.

• TinyRCT enables remote command ex*****on, file theft, screenshot capture, and persistent remote access.

• The operation demonstrates characteristics commonly associated with long-term cyber espionage campaigns designed to gather intelligence while remaining hidden.

Red Flags to Watch

• Unusual outbound connections to unfamiliar external servers.

• Unexpected remote command ex*****on or unauthorized administrative activities.

• Unknown processes running persistently in the background.

• Sudden creation or modification of scheduled tasks or startup entries.

• Suspicious file access or unexplained screenshot and data collection activities.

• Security tools generating repeated alerts for abnormal network behavior.

Recommendations

• Keep operating systems and applications fully patched and
updated.

• Implement Endpoint Detection and Response (EDR) solutions to identify malicious activity.

• Continuously monitor network traffic for unusual outbound communications.

• Apply the principle of least privilege to reduce unauthorized access.

• Conduct regular threat hunting and log analysis to detect indicators of compromise.

• Strengthen multi-factor authentication (MFA) and network segmentation for critical systems.

• Educate personnel on cybersecurity best practices and reporting suspicious activity promptly.

Conclusion

Advanced Persistent Threats continue to evolve by deploying custom malware specifically designed to evade traditional security measures and maintain long-term access to targeted networks.

Organizations must remain vigilant through layered security, continuous monitoring, and timely incident response to protect critical information and national infrastructure from emerging cyber threats.









CYBER ALERT: FAKE ADOBE & ZOOM UPDATESCybersecurity researchers have uncovered an active campaign dubbed SMOKE , where a...
20/08/2026

CYBER ALERT: FAKE ADOBE & ZOOM UPDATES

Cybersecurity researchers have uncovered an active campaign dubbed SMOKE , where attackers use fake Adobe and Zoom updates, business documents, and other software-related lures to trick users into executing malicious files. The campaign ultimately installs ConnectWise ScreenConnect, a legitimate remote-management tool that is abused by attackers to establish persistent remote access to compromised computers.

This campaign demonstrates how cyber threats can hide behind familiar software, trusted cloud platforms, and seemingly routine workplace activities. A legitimate application can become a security risk when attackers manipulate users into installing or running it without authorization.

KEY FACTS
• The campaign is identified as SMOKE .
• Attackers use fake Adobe and Zoom update notifications as phishing lures.
• Business-related documents and system-maintenance themes are also used to deceive users.
• The attack chain can involve VBScript droppers, batch scripts, .NET executables, PowerShell, and malicious MSI files.
• Attackers abuse trusted services, including Dropbox and Cloudflare, to deliver or stage malicious content.
• Successful infections lead to the installation of ScreenConnect, allowing attackers to establish persistent remote access.
• Attackers may attempt to weaken security protections such as AMSI, SmartScreen, and Windows Defender.

MALICIOUS SOFTWARE AND TOOLS IDENTIFIED
• ScreenConnect – legitimate remote-management software abused to maintain persistent remote access to compromised systems.
• VBScript droppers – used to initiate the infection and download additional payloads.
• PowerShell payloads – used to retrieve and execute malicious code.
• Malicious .NET loaders/executables – used to stage and execute the next phase of the attack.
• Malicious MSI installers – used to install the ScreenConnect client.
• Batch scripts – used to modify security settings and facilitate ex*****on.
• cloudflared.exe – a legitimate Cloudflare utility observed being used as part of the attackers' infrastructure and tunneling activity.

WARNING SIGNS
• Unexpected Adobe, Zoom, or software-update notifications received through email or web pages.
• Links directing users to download updates from unfamiliar websites or file-sharing services.
• Unexpected MSI, EXE, BAT, VBScript, or other executable files attached to emails or documents.
• Requests to disable antivirus, SmartScreen, or other security controls.
• Unexpected User Access Control (UAC) administrator prompts during supposedly routine software updates.
• Appearance of an unfamiliar remote-management or remote-access application on a workstation.
• Suspicious PowerShell or cmd.exe activity following the opening of an email attachment or downloaded file.

RECOMMENDATIONS
• Never install software updates from unsolicited email links or attachments.
• Download updates only from the software vendor's official website or approved organizational repositories.
• Verify unexpected update requests with your IT or cybersecurity personnel.
• Restrict the ex*****on of untrusted MSI, EXE, BAT, and script files.
• Monitor and audit the authorized use of Remote Monitoring and Management (RMM) tools such as ScreenConnect.
• Monitor suspicious PowerShell and command-line activity.
• Maintain endpoint security controls and investigate attempts to disable or tamper with security protections.
• Enforce appropriate UAC and application-control policies to prevent unauthorized administrative actions.
Cyber attackers do not always use obviously malicious software or suspicious websites; they can disguise their activities as routine software updates and legitimate business processes. Think before you click, verify before you install, and report suspicious activity immediately, because one seemingly harmless update can provide attackers with persistent access to your system.













CYBER ALERT | TinyRCT Backdoor Powering Cyber Espionage in Southeast AsiaCybersecurity researchers have uncovered a soph...
12/08/2026

CYBER ALERT | TinyRCT Backdoor Powering Cyber Espionage in Southeast Asia

Cybersecurity researchers have uncovered a sophisticated cyber espionage campaign involving a Chinese-speaking Advanced Persistent Threat (APT) group deploying a newly discovered backdoor called TinyRCT against government and state-owned energy organizations in Southeast Asia. The malware enables attackers to remotely control compromised systems, steal sensitive files, capture screenshots, and maintain long-term access while avoiding detection. The campaign highlights the persistent threat posed by nation-state actors targeting critical infrastructure and emphasizes the importance of proactive cyber defense.

Key Facts
• Researchers attributed the activity to a Chinese-speaking threat cluster tracked as CL-STA-1062.
• The campaign primarily targets government agencies and state-owned energy organizations in Southeast Asia.
• Attackers utilize a newly identified custom backdoor named TinyRCT.
• TinyRCT enables remote command ex*****on, file theft, screenshot capture, and persistent remote access.
• The operation demonstrates characteristics commonly associated with long-term cyber espionage campaigns designed to gather intelligence while remaining hidden.

Red Flags to Watch For
• Unusual outbound connections to unfamiliar external servers.
• Unexpected remote command ex*****on or unauthorized administrative activities.
• Unknown processes running persistently in the background.
• Sudden creation or modification of scheduled tasks or startup entries.
• Suspicious file access or unexplained screenshot and data collection activities.
• Security tools generating repeated alerts for abnormal network behavior.

Recommendations
• Keep operating systems and applications fully patched and updated.
• Implement Endpoint Detection and Response (EDR) solutions to identify malicious activity.
• Continuously monitor network traffic for unusual outbound communications.
• Apply the principle of least privilege to reduce unauthorized access.
• Conduct regular threat hunting and log analysis to detect indicators of compromise.
• Strengthen multi-factor authentication (MFA) and network segmentation for critical systems.
• Educate personnel on cybersecurity best practices and reporting suspicious activity promptly.

Advanced Persistent Threats continue to evolve by deploying custom malware specifically designed to evade traditional security measures and maintain long-term access to targeted networks. Organizations must remain vigilant through layered security, continuous monitoring, and timely incident response to protect critical information and national infrastructure from emerging cyber threats.








07/08/2026

CYBER ALERT | ClickLock: A New macOS Malware That Tricks You Into Giving Away Your Password

A newly discovered macOS malware called ClickLock is targeting Apple users through deceptive social engineering techniques rather than exploiting software vulnerabilities.

Victims are lured into copying and pasting malicious commands into the Terminal through fake verification pages, after which the malware disables system functions, displays convincing fake password prompts, and pressures users into revealing their macOS login credentials.

Once successful, it can steal browser data, password manager information, cryptocurrency wallets, and even install a persistent backdoor for remote access.

Key Facts

• Threat Name: ClickLock Stealer

• Targets macOS devices.

• Relies on social engineering, not software exploits.

• Often begins with a fake Cloudflare verification or ClickFix webpage.

• Tricks users into copying and running malicious commands in Terminal.

• Displays a fake macOS login prompt to steal the user's password.

• Can steal:
o Browser credentials and cookies
o Password manager data
o Cryptocurrency wallet information
o Autofill and session data
o Basic system information

• Installs a persistent backdoor that allows attackers to regain access to the device.

Red Flags

• A website asks you to copy and paste commands into Terminal.

• Fake CAPTCHA or Cloudflare verification pages requesting Terminal access.

• Unexpected macOS password prompts appearing after running Terminal commands.

• Finder, Dock, Terminal, or other applications suddenly close repeatedly.

• Your Mac becomes difficult to use while repeatedly asking for your login password.

Recommendations

• Never copy and execute Terminal commands from unfamiliar websites.

• Verify that software downloads come only from trusted or official sources.

• Be suspicious of websites requiring Terminal commands as part of "verification."

• Keep macOS and security software updated.

If your Mac suddenly locks up with persistent password
prompts, do not enter your password. Force a shutdown by holding the power button, then restart in Safe Mode and inspect the system for compromise.

Cybercriminals continue to rely on human deception instead of technical exploits. ClickLock demonstrates that even secure operating systems can be compromised when users are persuaded to perform unsafe actions. Practicing good cyber hygiene, questioning unusual requests, and avoiding unknown Terminal commands remain your strongest defenses against modern cyber threats.








CYBER ALERT | ClickLock: A New macOS Malware That Tricks You Into Giving Away Your PasswordA newly discovered macOS malw...
31/07/2026

CYBER ALERT | ClickLock: A New macOS Malware That Tricks You Into Giving Away Your Password

A newly discovered macOS malware called ClickLock is targeting Apple users through deceptive social engineering techniques rather than exploiting software vulnerabilities. Victims are lured into copying and pasting malicious commands into the Terminal through fake verification pages, after which the malware disables system functions, displays convincing fake password prompts, and pressures users into revealing their macOS login credentials. Once successful, it can steal browser data, password manager information, cryptocurrency wallets, and even install a persistent backdoor for remote access.

Key Facts
•Threat Name: ClickLock Stealer
•Targets macOS devices.
•Relies on social engineering, not software exploits.
•Often begins with a fake Cloudflare verification or ClickFix webpage.
•Tricks users into copying and running malicious commands in Terminal.
•Displays a fake macOS login prompt to steal the user's password.
•Can steal:
‣Browser credentials and cookies
‣Password manager data
‣Cryptocurrency wallet information
‣Autofill and session data
‣Basic system information
•Installs a persistent backdoor that allows attackers to regain access to the device.

Red Flags
•A website asks you to copy and paste commands into Terminal.
•Fake CAPTCHA or Cloudflare verification pages requesting Terminal access.
•Unexpected macOS password prompts appearing after running Terminal commands.
•Finder, Dock, Terminal, or other applications suddenly close repeatedly.
•Your Mac becomes difficult to use while repeatedly asking for your login password.

Recommendations
•Never copy and execute Terminal commands from unfamiliar websites.
•Verify that software downloads come only from trusted or official sources.
•Be suspicious of websites requiring Terminal commands as part of "verification."
•Keep macOS and security software updated.
•If your Mac suddenly locks up with persistent password prompts, do not enter your password. Force a shutdown by holding the power button, then restart in Safe Mode and inspect the system for compromise.

Cybercriminals continue to rely on human deception instead of technical exploits. ClickLock demonstrates that even secure operating systems can be compromised when users are persuaded to perform unsafe actions. Practicing good cyber hygiene, questioning unusual requests, and avoiding unknown Terminal commands remain your strongest defenses against modern cyber threats.








Fostering Interoperability: Joint Operational Visit to the 950th CEWWThe Commander of Cyber Command, AFP, BGEN JOEY T FO...
28/07/2026

Fostering Interoperability: Joint Operational Visit to the 950th CEWW

The Commander of Cyber Command, AFP, BGEN JOEY T FONTIVEROS PA, together with the Acting Commander of Air Logistics Support Command, BGEN EDMON B GUPIT PAF, conducted a Joint Operational Visit to the 950th Cyberspace and Electronic Warfare Wing (950 CEWW) on 22 July 2026 at the Headquarters, 950 CEWW, CJVAB, Pasay City. The delegation was warmly received by the Wing Commander, BGEN FERNANDO G VENTURA PAF, who welcomed the visiting commanders and provided an overview of the unit's operational capabilities and ongoing initiatives.

Strengthening inter-service collaboration and advancing unified cyber and electronic warfare capabilities, the visit served as an opportunity to reinforce coordination between Cyber Command, the Air Logistics Support Command, and the 950 CEWW in support of the Armed Forces of the Philippines' mission to enhance cyberspace operations and electronic warfare readiness. Discussions focused on operational synchronization, capability development, and fostering greater interoperability to effectively address emerging threats in the increasingly complex cyber and electromagnetic domains.

The engagement reaffirmed the commitment of the participating commands to work closely in building a more resilient, adaptive, and mission-ready force. Through sustained collaboration and shared expertise, Cyber Command, the Air Logistics Support Command, and the 950th Cyberspace and Electronic Warfare Wing continue to reinforce the AFP's ability to safeguard national security and maintain operational excellence across the cyber and electronic warfare battlespace.







Address

Camp General Emilio Aguinaldo
Quezon City
1110

Alerts

Be the first to know and let us send you an email when Cyber Command Armed Forces of the Philippines posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Organization

Send a message to Cyber Command Armed Forces of the Philippines:

Shortcuts

Share

Category