January 2026 summaries from specialist outlets described a China-linked APT cluster (reporting referenced designations such as UAT-8837) using the already-disclosed Sitecore CVE-2025-53690 ViewState / machineKey weakness as an initial-access path in critical infrastructure intrusions. The narratives built on late-2025 coordinated disclosure, CISA KEV listing, and enterprise forensic work around WeepSteel-class post-exploitation.
Canonical product-exploitation record: Sitecore CVE-2025-53690 exploitation wave on BreachHistory.
Source: The Hacker News