Chinese APT CL-STA-1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware

2026-06-27T02:51:42Zec8f3e3375bd222980b9c58c7c392df52db03db09a6c79cb176814bebbc59d67
CISACL-STA-1062CVE-2026-12569CVE-2026-20245FlexPLMKnown-Exploited-VulnerabilitiesPTC-WindchillTinyRCTaptbackdoorchina-linkedciscocritical-infrastructurecrypto-theftcurldata-breachmacOS.Gaslight (Gaslight)macospolymarketsd-wansoutheast-asiasupply-chaintata-electronicsthird-party-breachvulnerabilities

What happened

Multiple high-impact security developments: Palo Alto Unit 42 links Chinese-speaking APT CL-STA-1062 to persistent operations in East and Southeast Asia using custom tooling and a new TinyRCT backdoor targeting government and energy networks. Google/Mandiant reported active exploitation of Cisco Catalyst SD‑WAN zero-day CVE-2026-20245 months before disclosure, while CISA added Cisco and PTC Windchill/FlexPLM flaws (including CVE-2026-12569) to its Known Exploited Vulnerabilities catalog. Other notable incidents include a Polymarket third‑party supply-chain compromise that enabled ~$2.94M in盗/失

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
ec8f3e3375bd222980b9c58c7c392df52db03db09a6c79cb176814bebbc59d67
Enrichment time
2026-06-27T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.