Company Details
navseacareers
23,137
5,098
336
navy.mil
0
NAV_2665011
In-progress

Naval Sea Systems Command (NAVSEA) Careers Company CyberSecurity Posture
navy.milWe are NAVSEA. The Force Behind the Fleet. Join us and become part of a mission-driven team, at one of the best places to work in the federal government. This NAVSEA LinkedIn page is all about connecting with talented individuals ready to make a difference through a rewarding career with us. We share exciting job opportunities, recruitment events, highlight the NAVSEA mission, and show you how you can help support our warfighters and contribute to the Navy’s broader goals. When you join NAVSEA, you're joining a dynamic team committed to advancing naval capabilities. Whether you're an engineer, program manager, analyst, or IT professional, your work will directly impact the safety and success of our sailors, ensuring the Navy stays at the forefront of global maritime strength.
Company Details
navseacareers
23,137
5,098
336
navy.mil
0
NAV_2665011
In-progress
Between 750 and 799

NSSCC Global Score (TPRM)XXXX

Description: In January 2018, the **Naval Undersea Warfare Centre (NUWC)** in Newport, Rhode Island, suffered a severe **malware-driven data breach** orchestrated by Chinese state-sponsored hackers under the **Winnti Umbrella** campaign. The attackers exploited a **contractor’s system** to infiltrate NUWC’s network, exfiltrating **614GB of highly sensitive data**, including classified details of **Project Sea Dragon**—a critical undersea warfare initiative. The breach was part of a **decade-long espionage operation** targeting U.S. military and political entities, aiming to compromise national security assets. The stolen data likely included **proprietary defense technologies, operational plans, and intelligence**, posing a direct threat to U.S. naval capabilities. The incident underscored vulnerabilities in **supply chain security**, as third-party contractors became the entry point for advanced persistent threats (APTs). The breach’s scale and the nature of the compromised data suggest **long-term strategic consequences**, including potential advancements in adversarial military technology and compromised U.S. defense secrecy.


No incidents recorded for Naval Sea Systems Command (NAVSEA) Careers in 2025.
No incidents recorded for Naval Sea Systems Command (NAVSEA) Careers in 2025.
No incidents recorded for Naval Sea Systems Command (NAVSEA) Careers in 2025.
NSSCC cyber incidents detection timeline including parent company and subsidiaries

We are NAVSEA. The Force Behind the Fleet. Join us and become part of a mission-driven team, at one of the best places to work in the federal government. This NAVSEA LinkedIn page is all about connecting with talented individuals ready to make a difference through a rewarding career with us. We share exciting job opportunities, recruitment events, highlight the NAVSEA mission, and show you how you can help support our warfighters and contribute to the Navy’s broader goals. When you join NAVSEA, you're joining a dynamic team committed to advancing naval capabilities. Whether you're an engineer, program manager, analyst, or IT professional, your work will directly impact the safety and success of our sailors, ensuring the Navy stays at the forefront of global maritime strength.

At BAE Systems, we help our customers to stay a step ahead when protecting people and national security, critical infrastructure and vital information. We provide some of the world’s most advanced, technology-led defence, aerospace and security solutions and employ a skilled workforce of 107,000 peo
SAIC® is a premier Fortune 500 mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, civilian and intelligence markets includes secure high-end solutions in mission IT, enterprise IT

The Republic of Korea Air Force (ROKAF; Korean: 대한민국 공군; Hanja: 大韓民國 空軍; Revised Romanization: Daehanminguk Gong-gun), also known as the ROK Air Force, is the aerial warfare service branch of South Korea, operating under the South Korean Ministry of National Defense. The ROKAF has about 450 combat
Amentum is a global leader in advanced engineering and innovative technology solutions, trusted by the United States and its allies to address their most significant and complex challenges in science, security and sustainability. Our people apply undaunted curiosity, relentless ambition and boundles

We are a close-knit community of big thinkers collaborating to keep the world safe. Our passion, creativity and expertise bring next-level technology solutions to life in autonomous systems, cyber, C4ISR, strike, space, and logistics and modernization for our customers around the globe. On the Nor

Leidos is a Fortune 500® innovation company rapidly addressing the world’s most vexing challenges in national security and health. The company's global workforce of 48,000 collaborates to create smarter technology solutions for customers in heavily regulated industries. Headquartered in Reston, Virg
As a leading defence and security company, we offer solutions that range from the depths of the oceans to high in the sky, on land and in cyberspace, to keep people and society safe. Empowered by our 22,000 talented people, we constantly push the boundaries of technology to create a safer, more sus

As an international naval defence player, Naval Group is a partner for countries seeking to maintain control of their maritime sovereignty. Naval Group develops innovative solutions to meet its customers’ requirements. The group is present throughout the entire life cycle of vessels. It designs, pro

The world relies on what we do. Headquartered in Bethesda, Maryland, with offices across the U.S. and around the globe, our team delivers solutions that strengthen national security, shape industries and push engineering and technology to new levels. We collaborate to win. We put our customers fi
.png)
This summer, 10 high school students interning at Naval Undersea Warfare Center Division, Keyport through the Office of Naval Research's Science and...
Dr. Felicia Seals-Hilliard, currently serves as the Deputy Director of the Naval Sea Systems Command Equal Employment Opportunity Office (NAVSEA EEO).
The competition encourages students to develop advanced algorithms and models to enhance naval systems' cyber defense capabilities.
WASHINGTON -- Naval Sea Systems Command (NAVSEA) leaders gathered to celebrate outstanding performance demonstrated by individuals and teams...
The Puget Sound Naval Shipyard & Intermediate Maintenance Facility Command Career Center has transitioned from their old office in the...
WASHINGTON — Naval Sea Systems Command's (NAVSEA) Hull Maintenance Technician 1st Class Petty Officer Jennifer Schleuning was announced as...
NAVSEA, responsible for the acquisition, construction, maintenance, and inactivation of ships, submarines, and combat systems for the US Navy, celebrated its...
NATIONAL HARBOR, MD. — During a key panel at the 2024 Sea-Air-Space exposition, Erica Logan, deputy director for Workforce,...
WASHINGTON NAVY YARD – Naval Sea Systems Command (NAVSEA) Executive Director Giao Phan was honored at a retirement ceremony celebrating her...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Naval Sea Systems Command (NAVSEA) Careers is https://www.navsea.navy.mil/Careers/.
According to Rankiteo, Naval Sea Systems Command (NAVSEA) Careers’s AI-generated cybersecurity score is 765, reflecting their Fair security posture.
According to Rankiteo, Naval Sea Systems Command (NAVSEA) Careers currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Naval Sea Systems Command (NAVSEA) Careers is not certified under SOC 2 Type 1.
According to Rankiteo, Naval Sea Systems Command (NAVSEA) Careers does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Naval Sea Systems Command (NAVSEA) Careers is not listed as GDPR compliant.
According to Rankiteo, Naval Sea Systems Command (NAVSEA) Careers does not currently maintain PCI DSS compliance.
According to Rankiteo, Naval Sea Systems Command (NAVSEA) Careers is not compliant with HIPAA regulations.
According to Rankiteo,Naval Sea Systems Command (NAVSEA) Careers is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Naval Sea Systems Command (NAVSEA) Careers operates primarily in the Defense and Space Manufacturing industry.
Naval Sea Systems Command (NAVSEA) Careers employs approximately 23,137 people worldwide.
Naval Sea Systems Command (NAVSEA) Careers presently has no subsidiaries across any sectors.
Naval Sea Systems Command (NAVSEA) Careers’s official LinkedIn profile has approximately 5,098 followers.
No, Naval Sea Systems Command (NAVSEA) Careers does not have a profile on Crunchbase.
Yes, Naval Sea Systems Command (NAVSEA) Careers maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/navseacareers.
As of December 21, 2025, Rankiteo reports that Naval Sea Systems Command (NAVSEA) Careers has experienced 1 cybersecurity incidents.
Naval Sea Systems Command (NAVSEA) Careers has an estimated 2,373 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.
Title: Malware Attack and Data Breach at Naval Undersea Warfare Centre (2018)
Description: In January 2018, the Naval Undersea Warfare Centre in Newport, Rhode Island, was hit by a malware attack resulting in a data breach. Hackers targeted a contractor working for the center, stealing 614GB of highly sensitive data, including information about **Project Sea Dragon**. The incident is believed to be part of a decade-long Chinese state-sponsored hacking campaign nicknamed **'Winnti Umbrella'**, targeting political and defense entities.
Date Detected: 2018-01
Type: malware attack
Attack Vector: supply chain attack (via contractor)malware
Threat Actor: Chinese state-sponsored actorsWinnti Umbrella (APT group)
Motivation: cyber espionageintellectual property theftmilitary intelligence gathering
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through compromised contractor.

Data Compromised: 614GB
Brand Reputation Impact: potential damage to U.S. defense credibilityexposure of classified military projects
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Classified Military Project Data, Project Sea Dragon Details and .

Entity Name: Naval Undersea Warfare Centre (NUWC)
Entity Type: government/military research facility
Industry: defense
Location: Newport, Rhode Island, USA

Entity Name: Unnamed contractor (targeted as entry point)
Entity Type: third-party vendor
Industry: defense contracting

Type of Data Compromised: Classified military project data, Project sea dragon details
Sensitivity of Data: high (top-secret/confidential military intelligence)

Data Exfiltration: True

Regulations Violated: potential violations of U.S. defense secrecy laws (e.g., ITAR, EAR), classified information handling protocols,

Source: U.S. Department of Justice (DOJ) indictments related to Winnti Umbrella

Source: Cybersecurity reports on Chinese APT groups (e.g., FireEye, CrowdStrike)
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: U.S. Department of Justice (DOJ) indictments related to Winnti Umbrella, and Source: Cybersecurity reports on Chinese APT groups (e.g., FireEye, CrowdStrike).

Entry Point: compromised contractor
High Value Targets: Project Sea Dragon, Military R&D Data,
Data Sold on Dark Web: Project Sea Dragon, Military R&D Data,

Root Causes: Third-Party Vendor Security Weaknesses, Supply Chain Vulnerability,
Last Attacking Group: The attacking group in the last incident was an Chinese state-sponsored actorsWinnti Umbrella (APT group).
Most Recent Incident Detected: The most recent incident detected was on 2018-01.
Most Significant Data Compromised: The most significant data compromised in an incident was 614GB.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was 614GB.
Most Recent Source: The most recent source of information about an incident are U.S. Department of Justice (DOJ) indictments related to Winnti Umbrella, Cybersecurity reports on Chinese APT groups (e.g., FireEye and CrowdStrike).
Most Recent Entry Point: The most recent entry point used by an initial access broker was an compromised contractor.
.png)
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.
FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow. `generate_state_token()` is always called with an empty `state_data` dict, so the resulting JWT only contains the fixed audience claim plus an expiration timestamp. On callback, the library merely checks that the JWT verifies under `state_secret` and is unexpired; there is no attempt to match the state value to the browser that initiated the OAuth request, no correlation cookie, and no server-side cache. Any attacker can hit `/authorize`, capture the server-generated state, finish the upstream OAuth flow with their own provider account, and then trick a victim into loading `.../callback?code=<attacker_code>&state=<attacker_state>`. Because the state JWT is valid for any client for \~1 hour, the victim’s browser will complete the flow. This leads to login CSRF. Depending on the app’s logic, the login CSRF can lead to an account takeover of the victim account or to the victim user getting logged in to the attacker's account. Version 15.0.2 contains a patch for the issue.
FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.
LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.