Security News

Feds name and charge alleged Silk Typhoon spies behind years of China-on-US attacks
2025-03-06 00:47

Xi's freelance infosec warriors apparently paid up to $75K to crack a single American inbox US government agencies announced Wednesday criminal charges against alleged members of China's Silk...

China's Silk Typhoon, tied to US Treasury break-in, now hammers IT and govt targets
2025-03-05 17:22

They're good at zero-day exploits, too Silk Typhoon, the Chinese government crew believed to be behind the December US Treasury intrusions, has been abusing stolen API keys and cloud credentials...

China-Linked Silk Typhoon Expands Cyber Attacks to IT Supply Chains for Initial Access
2025-03-05 15:44

The China-lined threat actor behind the zero-day exploitation of security flaws in Microsoft Exchange servers in January 2021 has shifted its tactics to target the information technology (IT)...

Wallbleed vulnerability unearths secrets of China's Great Firewall 125 bytes at a time
2025-02-27 00:52

Boffins poked around inside censorship engines for years before Beijing patched hole Smart folks investigating a memory-dumping vulnerability in the Great Firewall of China (GFW) finally released...

Xi know what you did last summer: China was all up in Republicans' email, says book
2025-02-25 21:39

Of course, Microsoft is in the mix, isn't it Chinese spies reportedly broke into the US Republication National Committee's Microsoft-powered email and snooped around for months before being caught.…

China-based Silver Fox spoofs healthcare app to deliver malware
2025-02-25 16:17

Silver Fox, a China-based threat actor that may or may not be backed by the Chinese government, has been delivering the ValleyRAT backdoor to unsuspecting users by disguising the malware as...

China's Silver Fox spoofs medical imaging apps to hijack patients' computers
2025-02-25 13:15

Sly like a PRC cyberattack A Chinese government-backed group is spoofing legitimate medical software to hijack hospital patients' computers, infecting them with backdoors, credential-swiping...

Data Leak Exposes TopSec's Role in China’s Censorship-as-a-Service Operations
2025-02-21 16:06

An analysis of a data leak from a Chinese cybersecurity company TopSec has revealed that it likely offers censorship-as-a-service solutions to prospective customers, including a state-owned...

China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and Ransomware
2025-02-20 11:21

A previously unknown threat activity cluster targeted European organizations, particularly those in the healthcare sector, to deploy PlugX and its successor, ShadowPad, with the intrusions...

More victims of China's Salt Typhoon crew emerge: Telcos just now hit via Cisco bugs
2025-02-13 18:34

Networks in US and beyond compromised by Beijing's super-snoops pulling off priv-esc attacks China's Salt Typhoon spy crew exploited vulnerabilities in Cisco devices to compromise at least seven...