MEDIUMVulnerability
Global

ISMG Editors: How China Could Coerce Taiwan Without a War

·Source: Bank Info Security

Updated:

Executive Summary

Also, Healthcare's Resilience Test, Extortionists Struggle to Be Heard In this week’s update, ISMG editors discussed a think tank war game showing how China could cripple Taiwan’s communications short of invasion, why

Analysis

Also, Healthcare's Resilience Test, Extortionists Struggle to Be Heard In this week’s update, ISMG editors discussed a think tank war game showing how China could cripple Taiwan’s communications short of invasion, why healthcare cyber resilience is now measured by patient care and how attackers hit Asos customers with an in-app extortion message.

Indicators of Compromise (2)

URL (1)
https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ismg-editors-how-china-could-coerce-taiwan-without-war-image_small-10-a-33058.jpg
Domain (1)
ismg-cdn.nyc3.cdn.digitaloceanspaces.com
Source Attribution

Originally published by Bank Info Security on Oct 9, 2026.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-108707 — Wukong_HRM through commit 186115e contains an authentication bypass vulnerabilit...

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.

CVE-2026-108707
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-108598 — Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateE...

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.

CVE-2026-108598
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-108551 — openapi-typescript-codegen through 0.31.0 contains a code injection vulnerabilit...

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are importe

CVE-2026-108551
NIST NVD