<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>China-State on Security Unlocked</title><link>https://securityunlocked.com/tags/china-state/</link><description>Recent content in China-State on Security Unlocked</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 08 May 2026 13:00:00 +0000</lastBuildDate><atom:link href="https://securityunlocked.com/tags/china-state/index.xml" rel="self" type="application/rss+xml"/><item><title>Palo Alto Captive Portal Zero-Day Under Active Chinese-Linked Exploitation, First Patches May 13</title><link>https://securityunlocked.com/alerts/palo-alto-captive-portal-zero-day-under-active-chinese-linked-exploitation-first-patches-may-13/</link><pubDate>Fri, 08 May 2026 13:00:00 +0000</pubDate><guid>https://securityunlocked.com/alerts/palo-alto-captive-portal-zero-day-under-active-chinese-linked-exploitation-first-patches-may-13/</guid><description>CVE-2026-0300 (CVSS 9.3) is an unauthenticated, root-level RCE in the PAN-OS User-ID Authentication Portal of PA-Series and VM-Series firewalls, under active exploitation by a likely China-aligned cluster Unit 42 tracks as CL-STA-1132. First hotfixes ship May 13. Anything with the Captive Portal exposed to untrusted networks needs immediate mitigation.</description></item></channel></rss>