Vendor
high
advisory
Chinese-Speaking Operator Targets Philippine Nuclear and Naval Infrastructure
2 rules 3 TTPs 2 CVEsA suspected Chinese-speaking operator is targeting Philippine governmental and defense entities by exploiting ownCloud and LiteSpeed Cache vulnerabilities to exfiltrate personnel data and deploy loaders.
PoC
ownCloud +2
espionage
web-exploitation
data-exfiltration
2r
3t
2c
updated
medium
advisory
LiteSpeed Cache Plugin Stored XSS Vulnerability (CVE-2026-3375)
1 rule 1 TTP 1 CVEThe LiteSpeed Cache plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints, affecting versions up to 7.7, allowing unauthenticated attackers to inject arbitrary JavaScript into CCSS/UCSS content by bypassing IP-based access controls.
LiteSpeed Cache plugin for WordPress
cve
xss
wordpress
litespeed
plugin
1r
1t
1c