CLAIM · ASSESSED ~ · CONFIDENCE 0.50
Attackers allegedly used an old Digiwin single sign-on portal, built 2009-2011 on JDK 1.5/1.6, as the initial intrusion vector.
WHY THIS MATTERS · This matters because PRC hackers are already sitting inside the phone networks, power grids, and water systems Americans rely on, positioned to shut off or spy on critical services the moment a Taiwan or South China Sea crisis turns hot.
Part of the monitored dynamic PRC Infrastructure Intrusions · VUCA INDEX 68/100
EVIDENCE CHAIN · 0
PROVENANCE
Extracted by pipeline v0.5 (claude-opus-4-8) from ithome.com.tw · approved by christopher@vucanews.com JUL 18.
Extracted JUL 17; approved JUL 18 at 0.50.
MORE FROM THIS DYNAMIC
- Investigators identified a second backdoor, Stupig, on the same infected hosts as Daxin at the Taiwan manufacturer.
- Both Daxin and Stupig malware samples had early-2013 compile timestamps, suggesting up to 13 years of undetected presence.
- Symantec disclosed the Daxin backdoor four years ago, attributing it to China with activity traceable to 2013.
- CISA on 16 July 2026 added FortiSandbox flaws CVE-2026-39808 and CVE-2026-25089 to its KEV catalog, ordering federal agencies to patch by 19 July.
- CVE-2026-39808 and CVE-2026-25089 are OS command injection flaws rated CVSS 9.1; Fortinet issued patches in April and June 2026.
STRUCTURED DISSENT