Security News > 2021 > July > China Taking Control of Zero-Day Exploits
China is making sure that all newly discovered zero-day exploits are disclosed to the government.
Under the new rules, anyone in China who finds a vulnerability must tell the government, which will decide what repairs to make.
No information can be given to "Overseas organizations or individuals" other than the product's manufacturer.
No one may "Collect, sell or publish information on network product security vulnerabilities," say the rules issued by the Cyberspace Administration of China and the police and industry ministries.
It doesn't prevent researchers from telling the products' companies, even if they are outside of China.
News URL
https://www.schneier.com/blog/archives/2021/07/china-taking-control-of-zero-day-exploits.html
Related news
- North Korean ScarCruft Exploits Windows Zero-Day to Spread RokRAT Malware (source)
- Hackers exploit 52 zero-days on the first day of Pwn2Own Ireland (source)
- Lazarus hackers used fake DeFi game to exploit Google Chrome zero-day (source)
- Botnet exploits GeoVision zero-day to install Mirai malware (source)
- Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit (source)
- Chinese hackers exploit Fortinet VPN zero-day to steal credentials (source)
- China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer (source)