Skip to main content

Threats Affecting South Korea

View all threats affecting or targeting South Korea. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Country:South KoreaSouth Korea

Threats Affecting South Korea

Click on any threat for detailed analysis and mitigation recommendations

It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was discovered that libsoup did not remove proxy authentication credentials when following HTTP redirects. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1539) Ahmed Lekssays discovered that libsoup incorrectly parsed certain HTTP requests. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1801)

Join the discussion

A threat actor exploited CVE-2026-15409, a critical unauthenticated server-side request forgery vulnerability in SonicWall SMA1000 appliances, to gain command execution and steal credentials. The attacker used a modified public proof-of-concept exploit to access internal Erlang services on the appliance, enabling remote code execution. This allowed extraction of LDAP configurations, Active Directory credentials, and deployment of tools to dump secrets from internal Windows systems. The campaign targeted at least 250 SonicWall SMA1000 devices across multiple countries and sectors, with confirmed credential theft in France, India, Italy, and the US. The attack leveraged compromised appliances as pivots into internal networks, exposing sensitive Active Directory data and enabling DCSync attacks against domain controllers. The targeting was opportunistic and technology-driven rather than sector-specific. The campaign was uncovered through an open directory left exposed by the attacker, providing a comprehensive view of the operation.

Join the discussion

An unpatched zero-day vulnerability dubbed StyleSmuggler affects all current versions of Magento and Adobe Commerce, including 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code into Magento's template system using styles properties to evade safeguards, then executing the poisoned code via failed payment emails. Upon successful compromise, attackers deploy a Rust-based backdoor disguised as legitimate system processes (kworker, fc-cache, or chronyd) that connects to command and control servers. The backdoor uses NTP-shaped UDP traffic for C2 communication to evade detection. A second unrelated attacker has also been observed exploiting the same vulnerability to deploy PHP web shells. Affected merchants should deploy immediate mitigation measures, scan for compromise, and temporarily disable GraphQL until an official patch is released.

Join the discussion

A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

Join the discussion

Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]

Join the discussion
0

Metabase versions from 0.58.0 up to but not including 0.58.15, 0.59.0 up to but not including 0.59.12, 0.60.0 up to but not including 0.60.6.3, and 0.61.0 up to but not including 0.61.1.4 are affected by an authenticated remote code execution vulnerability. This vulnerability allows an authenticated attacker to execute arbitrary code remotely on the affected system.

Join the discussion

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]

Join the discussion

Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification even if the provided timestamp would mean the issuing certificate should be considered expired. When verifying artifact signatures using a certificate, Cosign first verifies the certificate chain using the leaf certificate's "not before" timestamp and later checks expiry of the leaf certificate using either a signed timestamp provided by the Rekor transparency log or from a timestamp authority, or using the current time. The root and all issuing certificates are assumed to be valid during the leaf certificate's validity. There is no impact to users of the public Sigstore infrastructure. This may affect private deployments with customized PKIs. This issue has been fixed in version 3.0.5.

Join the discussion

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]

Join the discussion

Showing 1 to 10 of 9666 results

Filters:Country: South Korea
Page 1 of 967
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses