China-nexus cyber espionage
CISA’s ‘CI Fortify’ Aims to Secure Critical Infrastructure During Conflicts
Jeffrey Burt | | China-nexus cyber espionage, CISA Advisory, Critical Infrastructure Cybersecurity, CyberAv3ngers, energy and utilities, Iran cyber capabilities, network segmentation, public water systems, Salt Typhoon, Telecommunications Security, Volt Typhoon, zero trust
CISA in its "Fortify CI" effort is warning critical infrastructure organizations like those in such sectors as energy, water, telecommunication, and healthcare about cyber threats that come with geopolitical conflicts and urging ...
Security Boulevard
China-Backed Groups are Using Massive Botnets in Espionage, Intrusion Campaigns
Jeffrey Burt | | BeyondTrust, Botnet Attack, China-linked Hackers, China-nexus cyber espionage, CISA Advisory, Flax Typhoon, IoT botnets, SOHO and IoT device vulnerabilities, Viakoo Labs, Volt Typhoon
China-sponsored threat groups like Salt Typhoon and Flax Typhoon are increasingly relying on multiple massive botnets comprising edge and IoT devices to run their cyber espionage and network intrusion campaigns, CISA and ...
Security Boulevard
China Hackers Using Brickstorm Backdoor to Target Government, IT Entities
Jeffrey Burt | | Brickstorm backdoor, China-nexus cyber espionage, cisa, Salt Typhoon, U.S. National Security Agency, Volt Typhoon
Chinese-sponsored groups are using the popular Brickstorm backdoor to access and gain persistence in government and tech firm networks, part of the ongoing effort by the PRC to establish long-term footholds in ...
Security Boulevard
ShadyPanda Takes its Time to Weaponize Legitimate Extensions
Teri Robinson | | affiliate fraud campaign, browser ecosystem vulnerabilities, browser extension supply chain attack, Browser Fingerprinting, browser surveillance tools, China-nexus cyber espionage, Chrome extension malware, cookie exfiltration, developer account compromise, Edge extension malware, enterprise browser security risk, extension review bypass, malicious auto-update pipeline, malicious JavaScript payloads, nuggetsno15 extensions, remote code execution extensions, search query harvesting, supply chain infiltration, unencrypted HTTP data leak, zero trust for browser security, Zhang Edge extensions
ShadyPanda spent seven years uploading trusted Chrome and Edge extensions, later weaponizing them for tracking, hijacking, and remote code execution. Learn how the campaign unfolded ...
Security Boulevard
App Stores OK’ed VPNs Run by China PLA
Richi Jennings | | 360 Security Technology, App Store, App Stores, Apple, CCP, china, china espionage, China-nexus cyber espionage, Chinese, Chinese Communists, Chinese cyber espionage, chinese government, free vpn app, google, Google Play Store, Peoples Republic of China, Privacy, Qihoo 360, SB Blogwatch, Signal Secure VPN, Snap VPN, Tech Transparency Project, Thunder VPN, TikTok, TikTok Ban, Turbo VPN, VPN, VPN Proxy Master
Bad Apple: Chinese firm banned by the U.S. is the shady entity behind a clutch of free VPN apps—with over a million downloads ...
Security Boulevard
Chinese DeepSeek AI App: FULL of Security Holes Say Researchers
Richi Jennings | | AI, AI (Artificial Intelligence), AI privacy, application-level encryption, Artificial Intelligence, Artificial Intelligence (AI), Artificial Intelligence (AI)/Machine Learning (ML), Artificial Intelligence Cybersecurity, Artificial Intelligence News, artificial intellignece, Artificial Stupidity, artificialintelligence, breach of privacy, Bytedance, California Consumer Privacy Act, California Consumer Privacy Act (CCPA), china, china espionage, China Mobile, China-nexus cyber espionage, Chinese, Chinese Communists, chinese government, Chinese Internet Security, Chinese keyboard app security, Congress, congressional legislation, cybersecurity artificial intelligence, Darin LaHood, Data encryption, Data encryption standards, Data Stolen By China, DeepSeek, DeepSeek AI, encryption, Josh Gottheimer, Large Language Models (LLM), Large language models (LLMs), LLM, llm security, No DeepSeek on Government Devices Act, Peoples Republic of China, Privacy, SB Blogwatch, TikTok, TikTok Ban, Unencrypted Data, US Congress
Xi knows if you’ve been bad or good: iPhone app sends unencrypted data to China—and Android app appears even worse ...
Security Boulevard
China is Still Inside US Networks — It’s Been SIX Months
Richi Jennings | | china, china espionage, China-linked Hackers, China-nexus cyber attacks, China-nexus cyber espionage, Chinese, Chinese cyber espionage, chinese hacker, Chinese hackers, Chinese Hacking Groups, Chinese state-sponsored cyberattacks, cisa, Crypto, cryptography, Data encryption, Data Stolen By China, E2EE, Earth Estries, email encryption, encryption, end-to-end encryption, FamousSparrow, FBI, Ghost Emperor, ISPs, Jeff Greene, nsa, Peoples Republic of China, Salt Typhoon, Salt Typhoon cyberattack, SB Blogwatch, Telecom Networks, UNC2286
Hell froze over: FBI and NSA recommend you use strong encryption ...
Security Boulevard
Ô! China Hacks Canada too, Says CCCS
Richi Jennings | | canada, Canadian Centre for Cyber Security, Canadian Government, china, china espionage, China-linked Hackers, China-nexus cyber attacks, China-nexus cyber espionage, Chinese, Chinese Communists, Chinese cyber espionage, chinese government, chinese hacker, Chinese hackers, Chinese Hacking Groups, Chinese Intelligence, Chinese state-sponsored cyberattacks, National Cyber Threat Assessment, Peoples Republic of China, SB Blogwatch
Plus brillants exploits: Canadian Centre for Cyber Security fingers Chinese state sponsored hackers ...
Security Boulevard
China Cyberwar Coming? Versa’s Vice: Volt Typhoon’s Target
Richi Jennings | | CenturyLink, china, china espionage, China-linked Hackers, China-nexus cyber attacks, China-nexus cyber espionage, CVE-2024-39717, Lumen, Lumen Technologies, Peoples Republic of China, SB Blogwatch, Versa Director, Versa Neworks, VersaMem, Volt Typhoon
Xi whiz: Versa Networks criticized for swerving the blame ...
Security Boulevard
Velvet Ant Exploits Cisco Zero-Day Flaw
Wajahat Raja | | China-nexus cyber espionage, Cisco NX-OS vulnerability, Command Injection Vulnerability, CVE-2024-20399, Cybersecurity News, Cybersecurity zero-day flaw
Recent events in the cybersecurity landscape have brought to light the activities of a China-nexus cyber espionage group known as Velvet Ant. The threat actor group has been observed exploiting a zero-day ...

