China Unicom Hong Kong operates as a telecommunications service provider, offering mobile connectivity services including 5G networks, IoT terminal connections, and virtual private network solutions for enterprise customers. The company also provides computing power services and security solutions as part of its telecommunications infrastructure business. UpGuard continuously monitors the security posture of China Unicom Hong Kong using open-source, commercial, and proprietary threat intelligence feeds. Our analysis is centered on objective, externally verifiable information.
China Unicom Hong Kong's security rating is based on the analysis of their external attack surface. The higher the rating, the better their security posture. Start a free trial to get a more in-depth risk assessment for China Unicom Hong Kong.
Last updated May 18, 2026
This vendor risk report is based on UpGuard's continuous monitoring of China Unicom Hong Kong's security posture using open-source, commercial, and proprietary threat intelligence feeds. The results are summarized into a security rating based on the analysis of hundreds of individual checks across five risk categories: website security, email security, phishing & malware, brand & reputation risk, and network security.
Browsers may display this website's content in frames. This can lead to clickjacking attacks.
The Content Security Policy may not restrict sources appropriately, or may contain 'unsafe-inline' without the use of a nonce or hash. This increases the risk of XSS attacks.
The Content Security Policy is implemented with unsafe-eval, reducing protection against XSS attacks.
Browsers may interpret files as a different MIME type than what is specified in the Content-Type HTTP header. This can lead to MIME confusion attacks.
This domain appears to be unmaintained based on indicators like page content or status code. Unmaintained pages expand the attack surface for malicious actors.
Using secure cookies reduces the risk of third parties intercepting information contained in these cookies.
Ensuring the server information header is not exposed reduces the ability of attackers to exploit certain vulnerabilities.
Information about specific technology used on the server is obscured.
The Content Security Policy does not allow any insecure active sources.
Using HttpOnly cookies reduces the risk of client side script attacks, by preventing cookies being read on the client.
The website's Referrer Policy is not configured to allow unsafe information to be sent in the referrer header.
Ensuring the ASP.NET version header is not exposing a specific version makes it harder for attackers to exploit certain vulnerabilities.
Ensuring the ASP.NET version header is not exposed makes it harder for attackers to exploit certain vulnerabilities.
The Content Security Policy does not allow any insecure passive (img/media) sources.
DMARC policy is p=none. This provides no protection against fraudulent emails. The DMARC policy should be migrated to p=quarantine, and eventually p=reject.
DMARC protects against fraudulent emails being sent from a domain.
Sender Policy Framework (SPF) records prevent spammers from sending messages with forged addresses.
Sender Policy Framework (SPF) record strictly enforces specific domains allowed to send email on its behalf.
Sender Policy Framework (SPF) record passes basic syntax checks.
Sender Policy Framework (SPF) record does not include the ptr mechanism.
The 'MySQL' service is running and exposed to the internet. The configuration of the server should be reviewed and unnecessary ports closed.
Port 10554 is open and an unidentified service was detected listening on this port. The configuration of the server should be reviewed and unnecessary ports closed.
Port 554 is open and an unidentified service was detected listening on this port. The configuration of the server should be reviewed and unnecessary ports closed.
The 'HTTP' service is running and exposed to the internet. The configuration of the server should be reviewed and unnecessary ports closed.
The 'HTTPS' service is running and exposed to the internet. The configuration of the server should be reviewed and unnecessary ports closed.
DNSSEC records prevent third parties from forging the records that guarantee a domain's identity. DNSSEC should be configured for this domain.
The domain does not contain a valid Certification Authority Authorization (CAA) record. A CAA record indicates which Certificate Authorities (CAs) are authorized to issue certificates for a domain.
No unregistered MX records that could lead to receiving mail on behalf of the target organization were detected.
No dangling DNS records that could lead to subdomain takeover were detected.
SSL is the standard encryption method for browsing websites. Enabling SSL requires installing an SSL certificate on the site.
The domain is still accessible over HTTP. All HTTP requests should be redirected to HTTPS.
The site's hostname does not match the SSL certificate. The domain name should be added to the certificate, either as a Subject Alternative Name or as the Common Name.
Without HSTS enforced, people browsing this site are more susceptible to man-in-the-middle attacks. The server should be configured to support HSTS.
Any version of the SSL protocol, and TLS prior to version 1.2, are now considered insecure. The server should disable support for these old protocols.
There is an invalid or missing intermediate certificate. This can cause some browsers to break the padlock. An intermediate/chain certificate may need to be installed to link it to a trusted root certificate.
Certificates issued on or after September 1, 2020 must not have a validity period greater than 398 days. The certificate will need to be reissued with a maximum validity of 397 days.
The domain was not found on the HSTS preload list. Users who visit the website for the first time will be vulnerable to MITM attacks. The requirements for inclusion on the preload list are specified by hstspreload.org.
Weak cipher suites can potentially be broken by a well resourced attacker, and should not be supported by the server unless very old devices or browsers must be supported.
The site's certificate chain was checked against our list of revoked certificates.
SSL certificate has not expired.
The certificate presented by this domain was issued by a trusted certificate authority.
SSL intermediate and root certificates do not expire within 20 days.
SSL certificate does not expire in less than 20% of its total valid period.
Industry standard SHA-256 encryption in use.
The HTTP Strict Transport Security (HSTS) header contains the includeSubDomains directive.
The site's public certificate provides at least 112 bits of security strength.
No cloud storage service configured to allow anonymous file listing was detected.
The domain index is not a listable directory.
This website does not appear to contain malicious code.
This IP/domain has not been reported as a source of botnet activity in the last 30 days.
This IP/domain did not appear on any list of IPs and domains known to perform brute force login attempts in the last 30 days.
This IP/domain has been reported for distributing malware in the last 30 days.
This IP/domain has not been reported for performing unsolicited scanning in the last 30 days.
This website does not appear to be attempting to install unwanted software.
This site does not appear to be a forgery or imitation of another website.
This IP/domain has not been reported as a phishing site in the last 30 days.
This IP/domain has not been reported as a source of botnet activity in the last 90 days.
This IP/domain did not appear on any list of IPs and domains known to perform brute force login attempts in the last 90 days.
This IP/domain has been reported for distributing malware in the last 90 days.
This IP/domain has not been reported for performing unsolicited scanning in the last 90 days.
This IP/domain has not been reported as a phishing site in the last 90 days.
A bug in OpenSSL's implementation of the TLS heartbeat extension allows access to portions of memory on the targeted host e.g. cryptographic keys and passwords.
The server does not support SSLv3, and is not vulnerable to the POODLE attack.
The server does not offer RSA_EXPORT cipher suites, so clients are not vulnerable to the FREAK attack.
The server is using strong Diffie-Hellman parameters and is not vulnerable to the Logjam attack.
Compare China Unicom Hong Kong's security performance with other companies in their industry.
Yahoo! operates an internet media platform providing web portal services including email, news aggregation, search functionality, weather information, and financial data. The company delivers content across multiple categories such as sports, entertainment, lifestyle, and politics to users in various international markets.
Canva operates an online graphic design platform that enables users to create visual content including presentations, social media graphics, posters, and documents. The platform provides templates, design tools, and a library of images and fonts accessible through a web browser and mobile applications.
NVIDIA designs and manufactures graphics processing units (GPUs) and system on a chip units for computing applications. The company provides hardware and software platforms for artificial intelligence, data centers, high-performance computing, gaming, professional visualization, and automotive markets.
Apple designs and manufactures consumer electronics, computer software, and online services. The company's product lineup includes smartphones, tablets, personal computers, smartwatches, and audio devices, along with operating systems and digital content distribution platforms.
Adobe develops and publishes software products for creative professionals, marketers, and enterprises. The company offers applications for graphic design, video editing, web development, photography, and document management. Its products are primarily delivered through cloud-based subscription services.
LinkedIn operates a professional networking platform that connects professionals, employers, and job seekers. The service enables users to create professional profiles, build business networks, search for employment opportunities, and access educational courses and industry content.
The ultimate guide to attack surface and third-party risk management – actionable advice for security teams, managers, and executives.
Security research and global news about data breaches.
Explore resourcesArticles, news, and research on third-party risk management.
Explore resourcesArticles, news, and research on attack surface management.
Explore resourcesArticles, news, and research on cybersecurity.
Explore resources