Forwarded National Information Sharing and Analysis Center Information Security Alert NICS-ANA-2026-0000741
[Content Description]
In response to emerging AI cybersecurity threats and cybersecurity incidents, please have all agencies conduct a comprehensive review and inventory (including systems deployed in the cloud) and register and manage the following items, including systems, equipment, and websites that should not be publicly accessible.
I. Systems and websites that are no longer needed, idle, or should be taken offline but have not yet been taken offline.
II. Test machines, jump servers, test systems, backup and disaster recovery systems that should not be exposed to the external network.
III. Legacy systems and network communication equipment that can no longer receive security updates but still need to be used.
If you have any related questions, please contact the Administration for Cyber Security at 02-2380-8500 and speak with customer service personnel.
[Impacted Platform]
As detailed in the Content Description
[Recommended Actions]
Please have all agencies implement the following cybersecurity protection measures and complete them within 1 month, and report the results to the agency Chief Information Security Officer:
I. Systems and websites that are no longer needed, idle, or should be taken offline but have not yet been taken offline: Stop services or take them offline.
II. Test machines, jump servers, test systems, backup and disaster recovery systems that should not be exposed to the external network: Move them to an internal network environment, do not directly provide Internet access externally, and disable unnecessary services and communication ports.
III. Legacy systems and network communication equipment that can no longer receive security updates but still need to be used: Adopt corresponding mitigation measures such as a separate network segment, or establish a replacement schedule.