South Korea’s KISA Launches Proactive Removal Service for Vulnerable WGear Banking Middleware
WGear is middleware commonly used by South Korean companies for online banking. Older versions contain a remote code execution, or RCE, vulnerability that attackers could exploit to run malicious software, threatening account operations and electronic financial services. The Korea Internet & Security Agency, or KISA, therefore selected WGear as the first target of its proactive removal program.
KISA launched its Vulnerability Removal Service for the first time in April 2026, partnering with four antivirus software vendors to proactively detect and remove older WGear versions containing the vulnerability through their antivirus products. The initiative marks a shift from issuing warnings and asking users to install updates themselves to directly helping remove risky software.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.