News
-
MoreTing-Wei Hsieh (CHT Security Co)As detection and response toolsets are actively being developed and deployed on common Windows and Linux devices, edge devices remain largely reliant on system configurations and human intervention as their main defence. Nevertheless, nation-state attackers have increasingly been targeting public-facing appliances as initial entry points to gain footholds in victims environments and their tactics have shown great effectiveness.In early 2024, we uncovered an attack that lasted several years against a high-tier local cloud service provider. The techniques and novel samples we found show both the efforts attackers have made to understand commercial edge-device systems and the great lengths attackers are willing to go to reduce the chance of being detected. Although the concept of magic packets is nothing new, we discovered that attackers have been moving from static magic signatures and hard-coded C2 configurations to fully dynamic and more versatile magic packets to evade network-based detections.In this talk, I will share how security appliance mishaps may lead to attacks of such a scale and will focus on the evasion techniques observed in this attack, such as the usage of magic packets with no static signature and utilizing living-off-the-land (LotL) tools to extract sensitive data on compromised edge devices. In addition, the session will present our insights to detect and mitigate persistent installations emerging from this attack and some general recommendations or mitigation methods for both service providers and public-facing appliance suppliers.For details please visit Virus Bulletin Website.
-
CHT Security H1 EPS Hits Record High of NT$6.16 as AI Emerges as New Revenue Engine
MoreCHT Security (TWSE: 7765) was invited to hold its Q2 2026 earnings call on August 5. For the first half of 2026, consolidated revenue reached NT$1.182 billion, up 21% year-over-year (YoY); net profit after tax reached NT$251 million, up 13% YoY; and earnings per share (EPS) stood at NT$6.16. Both revenue and net profit set new record highs for the same period. Continuing this momentum, the newly released July revenue reached NT$210 million, up 9% YoY, bringing cumulative revenue to NT$1.392 billion, representing a cumulative YoY growth of 19% and continuing to set new historical highs.CHT Security stated that in the first half of the year, recurring revenue, including Network Security subscription and SOC/MDR Security Monitoring Services, grew by 8.7% YoY, accounting for 47% of total revenue, primarily driven by steady customer base expansion and high retention rates. Non-recurring project-based revenue accounted for 53% of total revenue, largely fueled by strong demand across sectors such as government, finance, healthcare, and high-tech manufacturing to fulfill cybersecurity risk management requirements. Among these, revenue from proprietary products grew by 54% YoY, accompanied by the launch of a new AI cybersecurity product, AI Archway. In overseas markets, robust demand from semiconductor and financial sectors propelled overseas revenue up by 233% YoY.Analyzing revenue drivers, Frontier AI Models now possess the capabilities to rapidly discover and exploit security vulnerabilities, compelling many enterprises to proactively address vulnerability assessment and remediation earlier than planned. This shift has driven a sharp increase in order volume for Red Teaming Exercises, Penetration Testing, and AI Application Security Testing. Another major AI-driven demand lies in AI Governance. Governments and enterprises face challenges in controlling how employees utilize AI tools, giving rise to risks such as sensitive data leakage, unexpected cost inflation, and content misuse. The rapid market recognition and strong response following the recent rollout of AI Archway validate that AI will serve as a key new catalyst driving cybersecurity revenue growth.Looking ahead to the second half of 2026, recurring revenue is expected to maintain steady growth. Combined with non-recurring project contracts valued at NT$600 million to NT$700 million slated for H2, the overall annual revenue growth trajectory is well established. Furthermore, driven by emerging AI-powered demand, spanning AI Security Assessment, AI SOC, and the new AI Archway governance products and services, the company expects its operational growth momentum to remain strong throughout the entire year.In addition to deepening its market presence, CHT Security actively contributes to public-interest anti-fraud initiatives. At the end of July, the company officially launched the Scam-Fighter App, available for free download by the public. Built on proprietary patented AI recognition technology, the App automatically analyzes content features of incoming messages to effectively identify potential risks. Once installed, it automatically detects suspicious messages without collecting any personal data during the detection process, delivering real-time anti-fraud protection while safeguarding user privacy and data security.
-
CHT Security Awarded Taiwan Cybersecurity Services Company of the Year Award by Frost & Sullivan
MoreCHT Security Awarded Taiwan Cybersecurity Services Company of the Year Award by Frost SullivanThe Transformation of the Cybersecurity Services IndustryTaiwans cybersecurity services market is entering a new phase of growth as enterprises accelerate the adoption of artificial intelligence (AI), cloud-native architectures, and increasingly interconnected digital ecosystems. While these technologies create significant opportunities for innovation and operational efficiency, they also expand the cyber threat landscape by introducing new attack vectors, more sophisticated adversaries, and greater operational complexity. Organizations are therefore seeking cybersecurity partners that can deliver continuous monitoring, advanced threat detection, and strategic guidance while helping them securely adopt emerging technologies.At the same time, the role of managed and professional security service providers continues to evolve beyond traditional monitoring and incident response. Customers increasingly expect providers to deliver proactive threat intelligence, AI-driven analytics, cloud security expertise, offensive security testing, and governance capabilities that address both current operational risks and long-term digital transformation initiatives. As AI adoption accelerates across enterprises, cybersecurity providers must also help organizations manage risks associated with AI applications, data protection, and regulatory compliance.Defending the AI Frontier: Closing the Next-Generation Security GapFounded in 2017, CHT Security has established itself as a prominent cybersecurity services provider in Taiwan, with a strategic focus on addressing emerging risks associated with AI adoption and digital transformation. Through continued investment in AI-enabled security operations, proprietary technologies, and integrated managed and professional security services, the company supports organizations in strengthening cyber resilience across increasingly complex IT environments. Its portfolio spans security operations, AI security assessments, cloud security, offensive security services, and governance-focused capabilities designed to help enterprises respond to evolving cybersecurity requirements.CHT Securitys emphasis on technology innovation, operational execution, and customer-centric service delivery differentiates the company within Taiwans cybersecurity services market. By combining AI-enabled security operations with proprietary research capabilities and a broad portfolio of managed and professional services, the company demonstrates a forward-looking approach that enables customers to navigate emerging cyber risks while supporting secure digital transformation. These strengths provide a solid foundation for continued growth and reinforce CHT Securitys position as a leading cybersecurity services provider in Taiwan.The rapid adoption of AI technologies has introduced a new set of cybersecurity considerations as organizations seek to protect AI models, data pipelines, and AI-enabled business processes alongside traditional IT infrastructure. This evolution has increased demand for cybersecurity services that provide stronger governance, enhanced visibility, and specialized protection for AI deployments.CHT Security has responded to these requirements by expanding its AI-enabled security operations center (SOC) capabilities. The companys AI-powered SOC integrates proprietary AI technologies into its security risk management platform to support real-time threat detection, incident analysis, and automated reporting. Through natural language interfaces and AI-assisted analysis, security teams can more efficiently interpret events, prioritize response activities, and streamline investigation workflows.Beyond security monitoring, CHT Security has broadened its portfolio with AI-focused security assessment services designed to evaluate emerging risks associated with enterprise AI adoption. Its AI application testing services assess issues such as prompt injection, model manipulation, sensitive information disclosure, and other vulnerabilities by leveraging recognized industry frameworks and offensive security methodologies. These assessments are complemented by practical remediation guidance that helps organizations strengthen the security of AI-enabled environments.The company also offers AI cybersecurity posture assessment services that evaluate governance mechanisms, operational controls, and technical safeguards surrounding AI deployment and usage. By identifying potential gaps and recommending improvements, these assessments help organizations establish more secure and sustainable AI governance practices.Collectively, these capabilities demonstrate CHT Securitys ability to anticipate and address the evolving security demands of AI-driven enterprises. By embedding intelligence, automation, and governance into its service portfolio, the company enables organizations to adopt AI with greater confidence while maintaining robust security controls. This forward-looking approach not only addresses immediate customer needs but also positions CHT Security at the forefront of securing next-generation digital ecosystems.Architecting the Future: Leveraging Megatrends into Strategic AdvantageCHT Security has aligned its cybersecurity strategy with major technology megatrends, particularly the convergence of AI, cloud computing, and digital transformation. Rather than viewing these developments solely as sources of risk, the company has expanded its service portfolio to help customers both leverage AI securely and strengthen cybersecurity operations through AI-enabled capabilities.A notable example is Archway, the companys platform designed to improve visibility into enterprise AI usage while supporting governance and security controls. The platform provides centralized monitoring of AI-related activities, helps organizations identify unauthorized AI usage, incorporates organization-specific data leakage protection capabilities, and supports policy enforcement and compliance monitoring. These capabilities enable customers to adopt AI technologies while maintaining greater oversight and control over associated risks.The company has also continued to invest in technical research and innovation. According to CHT Security, it has reported more than 150 common vulnerabilities and exposures (CVEs), reflecting sustained investment in vulnerability research and technical expertise. At the same time, it has expanded cloud security capabilities and AI-enabled security services to address evolving customer requirements across hybrid and multi-cloud environments.Frost Sullivan finds that CHT Securitys ability to align service innovation with emerging technology trends strengthens its competitive positioning within Taiwans cybersecurity services market. By combining AI-enabled security operations, AI governance capabilities, and cloud-focused security services, the company is well positioned to support organizations as they navigate increasingly sophisticated cybersecurity challenges.Operational Discipline and Scalable Excellence: Turning Strategy into ResultsBeyond technology innovation, CHT Security places strong emphasis on operational excellence and service resilience to ensure the consistent delivery of cybersecurity services. The company continues to strengthen its business continuity capabilities and is in the process of obtaining ISO 22301 certification, reinforcing its commitment to operational preparedness, risk management, and service continuity. This disciplined approach enables the organization to support customers with mission-critical security operations while maintaining high standards of reliability and governance.The company has also demonstrated its ability to execute large-scale and technically complex cybersecurity engagements across a broad range of industries. CHT Security has secured projects involving AI security assessments, managed detection and response, red teaming, and large-scale network security deployments for customers spanning government agencies, financial institutions, semiconductor manufacturers, and other critical sectors. These engagements highlight the breadth of its technical expertise and its ability to address diverse cybersecurity requirements.Rather than competing primarily on price, CHT Security focuses on delivering long-term value through comprehensive cybersecurity services that span prevention, monitoring, incident response, and post-incident support. By combining managed and professional security services with proprietary technologies and technical expertise, the company provides organizations with an integrated approach to strengthening cyber resilience while supporting evolving business and regulatory requirements.Customer Trust as a Differentiator: Delivering End-to-End Experience ExcellenceCustomer engagement and long-term relationships remain central to CHT Securitys operating philosophy. The companys customer retention rates exceed 90%, reflecting sustained relationships built on service quality, technical expertise, and ongoing collaboration indicative of strong satisfaction levels and a proven ability to meet evolving client needs. Structured engagement practices, including regular feedback collection, continuous service optimization, and proactive communication, form the backbone of this achievement. By maintaining close alignment with its customers, the company ensures that its offerings remain relevant and effective.The integration of AI-driven tools within its services enhances the customer ownership experience. By simplifying complex security processes and providing actionable insights, these tools empower organizations to take greater control of their security posture. This combination of advanced technology and user-centric design creates a seamless and rewarding experience for customers.CHT Securitys brand strength is further reinforced by its commitment to integrity and professionalism. Its corporate values emphasize reliability, expertise, and a global outlook, all of which resonate strongly with customers. The companys willingness to extend support beyond contractual obligations highlights its long-term perspective and reinforces its reputation as a trusted advisor.Customers often view their association with CHT Security as a mark of quality, reflecting the companys strong brand equity within the market. This perception not only enhances customer confidence but also contributes to broader market recognition and growth.Through its emphasis on trust, service excellence, and customer empowerment, CHT Security delivers a comprehensive experience that extends beyond technical performance to encompass lasting business value.For details please visit Frost Sullivan website.
-
MoreCHT Security is honored to once again receive Frost Sullivans 2026 Taiwan Company of the Year recognition in the Cybersecurity Services Industry. This prestigious recognition highlights CHT Securitys outstanding achievements in AI-powered Security Operations Center (AI SOC), AI Application Security Testing, and the AI Archway cybersecurity platform, as well as its exceptional customer retention rate of over 90%.Driven by continuous innovation and operational excellence, CHT Security remains committed to delivering industry-leading cybersecurity technologies and trusted security services, empowering organizations with resilient and comprehensive cyber defense against todays evolving threat landscape.
-
CHT Security Delivered Speech at DEF CON Sinpapore 2026
MoreTurning Spam Filters Into Your Greatest Enemy: Intrusions Via RCEs in E-Mail Spam FiltersTing-Wei Hsieh CHT Security Co., Ltd.Kai-Ching Wang CHT Security Co., Ltd.In the last couple of years, APTs targeting critical organizations in Taiwan have exploited multiple 0-day and N-day vulnerabilities in popular local email server software. Advertised as advanced defenses that stop APT attacks, such filters are supposed to check the contents and attachments of all inbound emails and block potential threats. In contrast to the claims, those spam filters became the very entry point of several high-profile intrusions, leading to zero-interaction compromises of high-value targets. From command injection to digital cluster bombs combining automated shellcode injection and a kernel module backdoor, attackers were able to get full control of a target system with just a single crafted email.In this session, I will share cases of real-world APT intrusions via exploiting vulnerabilities in email server software from different vendors, along with sophisticated malware used in the attacks. I will also share our recommendations to mitigate such risks for vendors alike. Our findings suggest that nation-state actors have already gained a comprehensive understanding of the inner workings of popular email server software in target regions, marking the importance of security awareness in the development of such public-facing software.Ting-Wei HsiehTing-Wei is a malware analyst at CHT Security Co., Ltd, working primarily in the incident response team that constantly deals with APT attacks and novel malware. As a self-taught reverse engineer, Ting-Wei is interested in Windows static and dynamic malware analysis, x64 obfuscation, packing and evasion techniques.Kai-Ching WangKai-Ching Wang (Keniver) is a Senior Security Researcher at CHT Security. He specializes in red team assessments and comprehensive security reviews, with a current focus on hacking IoT devices and cloud-native infrastructure. He has presented his research on the security of cloud-connected IoT camera systems at conferences such as SECCON in Japan and HITCON in Taiwan.For details please click here.
-
MoreCHT Security (TWSE: 7765) today announced its unaudited financial results for the first half of 2026. Consolidated revenue for June reached NT$188 million, a 26% increase month-over-month and a 6% increase year-over-year. Cumulative revenue for the first half of the year was NT$1.182 billion, a 21% increase year-over-year, with cumulative net profit after tax of NT$251 million, a 13% increase year-over-year, and EPS of NT$6.16.In addition to steady growth in recurring revenue streams, such as network security and Security Operations Center (SOC) monitoring services, performance was primarily driven by the rapid evolution of artificial intelligence. As enterprises place greater emphasis on exposure management, demand for cybersecurity assessment services, including penetration testing and red team exercises, has surged. Furthermore, recognizing the rising enterprise focus on AI governance, CHT Security strategically launched AI Archway to address the mandatory requirements of corporate AI administration and risk management, driving both revenue and profitability to record high levels for the period.CHT Security highlighted that many advanced AI models now possess autonomous vulnerability discovery and exploitation capabilities, enabling them to execute automated attacks. This reality forces enterprises to accelerate vulnerability exposure management. To preempt malicious threat actors, businesses are proactively retaining professional cybersecurity firms to uncover vulnerabilities and remediate security gaps, triggering substantial growth in demand for penetration testing and red team services.With the widespread adoption of AI technologies and applications across industries, AI governance has become a paramount executive agenda. In response, CHT Security introduced its self-developed governance platform, AI Archway. Operating via browser extensions or endpoint agents combined with an AI security gateway, the system establishes a robust AI governance framework that prevents sensitive data exfiltration.The platform supports data tokenization (anonymization) before sending requests to external public AI services, and seamlessly performs detokenization upon receiving responses to restore original business workflows. Additionally, AI Archway acts as a real-time guardrail by filtering harmful responses generated by external LLMs, enforcing token usage quotas, and preventing prompt injections or jailbreak bypasses. Through an intuitive management dashboard, enterprises can continuously monitor regulatory compliance and evaluate operational risks associated with AI deployment.Jeff Hung, General Manager of CHT Security, stated, AI Archway functions much like an airport security checkpoint system. It encourages people to travel abroad freely, but ensures prohibited items are restricted during departure and agricultural or biosecurity hazards are intercepted upon arrival. Only with such an effective management architecture can enterprises achieve both operational efficiency and robust security. Our objective with AI Archway is to enable safe AI adoption by empowering organizations with four core capabilities: Visibility, Defensibility, Contextual Awareness, and Governability.Via the dashboard, organizations can gain complete insight into corporate AI usage patterns and detect unauthorized Shadow AI risks. The platform supports major AI platforms, ensuring that employees view unmasked original content while external AI models process masked tokens, balancing productivity with data privacy. It also employs customized Data Loss Prevention (DLP) models trained on enterprise-specific confidential data to identify trade secrets, manufacturing processes, proprietary formulas, and legal contractscatering to demanding sectors including finance, healthcare, government, semiconductor, and high-tech industries. By aligning decision-making and auditing workflows with regulatory frameworks such as GDPR and the Personal Data Protection Act (PDPA), the system automatically generates compliance and risk assessment reports to help enterprises enforce AI governance.Directly addressing the inelastic demand for AI governance, CHT Security expects AI Archway alongside its specialized AI cybersecurity solutions to inject sustained growth momentum into company operations moving forward.
-
CHT Security Delivered a Speech on AI Application Testing at DCCI Vietnam
MoreCHT Security delivered a speech Security Testing Approaches and Attack Detection Practices for AI Application Systems during DCCI (data center cloud infrastructure) Summit at Ho Chi Minh City, Vietnam on June 16, 2026. Andrea Liang will talk about the latest AI trend and how to protest enterprises with AI Application Testing.For more information: https://dccisummit.viettelidc.com.vn/en/chuong-trinh-hoi-thao-2026-tp-ho-chi-minh/
-
MoreThank you for attending CHT Security S2W joint seminar Proactive Enterprise Defense from the Dark Web to the AI Era.
-
MoreCHT Security (TWSE: 7765) announced its financial results for May 2026, reporting a monthly revenue of NT$150 million, a 3% increase year-on-year (YoY). Cumulative revenue for the first five months reached NT$993 million, representing a robust YoY growth of 24%. Driven by surging demand for AI cybersecurity, Red Teaming, and penetration testing, alongside steady expansion in recurring revenue streams such as internet security services and SOC/MDR (Security Operations Center / Managed Detection and Response), the company continues to demonstrate a trajectory of stable growth in both top-line revenue and profitability. To further accelerate business momentum, CHT Security has recently launched its new DNS Guardian service and an Enterprise AI Governance service.CHT Security convened its 2026 Annual General Meeting (AGM) of Shareholders on May 28, during which shareholders approved the 2025 Business Report, Financial Statements, and Earnings Distribution Plan. The companys revenue and net income for the fiscal year 2025 both achieved consecutive historical highs. The AGM resolved to distribute a cash dividend of NT$9.66 per share. The ex-dividend trading date is scheduled for June 18, 2026, and the cash dividend distribution is expected to commence on July 17, 2026.In product innovation, CHT Security recently debuted its DNS Guardian service. By establishing a DNS defense system at the telecom-datacenter level, the service leverages real-time threat intelligence matching and AI-assisted risk analysis to help enterprise clients immediately block connection threats such as botnets, malicious domains, phishing sites, and newly registered high-risk domains. Furthermore, it identifies and mitigates threats within encrypted traffic, significantly enhancing the defense depth and cyber resilience of enterprise internet access. The service also provides timely intercept protection reports, offering enterprises clear visibility into network risks. This defense solution is fully compatible with various broadband speeds and existing cybersecurity services.Additionally, CHT Security participated in the recent COMPUTEX Taipei, showcasing its proprietary AI Governance services. These solutions assist enterprises in managing Shadow AI, preventing leaks of sensitive corporate data, and providing continuous AI SOC monitoring. By increasing brand visibility and driving domestic and international sales, these initiatives are expected to accelerate market expansion and fuel further growth in revenue and profitability.
-
Visit us during COMPUTEX 2026!
MoreAs AI transforms the tech landscape, cybersecurity must evolve. Visit our booth at COMPUTEX 2026 to experience our cutting-edge security ecosystem in action:SecuTex NP Real-time network anomaly detection at your internet gateway.SecuTex ED Seamless policy enforcement and automated malware hunting across endpoints.AI SOC Next-gen security operations leveraging AI to supercharge your detection and response capabilities.Dont miss out on securing your business for the AI era. Schedule a meeting or drop by to chat with our team!Date: June 2 5, 2026Time: 9:30 AM 5:30 PM (Closes at 3:30 PM on June 5)Venue: 4F, Taipei Nangang Exhibition Center, Hall 2 (TaiNEX 2)Booth: R0632
For Financial Institutions
Security Assessment, ATM Drills for Offense & Defense, DDoS Drills, GDPR Consultant.
For Enterprises
Large Enterprises: Gateway Protection, Endpoint Protection, Data Security, Regular assessment, ISMS, In-depth Defense with ISPs.
SMB & Soho: Anti-virus, Anti-hacking, Internet Protection.
For Government Departments
Regulation Compliance, Regional Joint Defense, SOC, ISAC, Common Supply Contract.