Security News

China-backed Hackers Hijack Software Updates to Implant "NSPX30" Spyware
2024-01-25 10:08

A previously undocumented China-aligned threat actor has been linked to a set of adversary-in-the-middle (AitM) attacks that hijack update requests from legitimate software to deliver a...

Russians invade Microsoft exec mail while China jabs at VMware vCenter Server
2024-01-20 00:08

A VMware security vulnerability has been exploited by Chinese cyberspies since late 2021, according to Mandiant, in what has been a busy week for nation-state espionage news. On Friday VMware confirmed CVE-2023-34048, a critical out-of-bounds write flaw in vCenter Server, was under active exploitation.

US agencies warn made-in-China drones might help Beijing snoop on the world
2024-01-19 02:45

Two US government agencies, the Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation, warned on Wednesday that drones made in China could be used to gather information on critical infrastructure. How Wi-Fi spy drones snooped on financial firm FCC suggests licensing 5GHz spectrum to drone operators Wing, Alphabet's drone delivery unit, designs bigger bird to deliver pasta, faster US lawmakers have Chinese LiDAR on their threat-detection radar.

Nokia walks the walk about its RAN to play on Uncle Sam’s China fears
2024-01-17 02:59

Over the past few administrations, the US government has worked tirelessly to rid its national networks of Chinese-made equipment from the likes of Huawei and ZTE over fears its presence could give Beijing insights into, or access to, networks relied on by the United States and its allies. RAN deployments by US carriers most feature kit from Samsung, Nokia, and Ericsson.

China’s gambling crackdown spawned wave of illegal online casinos and crypto-crime in Asia
2024-01-16 03:30

Global crime networks have set up shop in autonomous territories run by armed gangs across Southeast Asia, and are using them to host physical and online casinos that, in concert with crypto exchanges, have led to an explosion of money laundering, cyberfraud, and cybercrime across the region and beyond. The scenario above was outlined on Monday by the United Nations Office on Drugs and Crime in a new report [PDF] titled "Casinos, Money Laundering, Underground Banking, and Transnational Organized Crime in East and Southeast Asia: A Hidden and Accelerating Threat."

China loathes AirDrop so much it's publicized an old flaw in Apple's P2P protocol
2024-01-15 02:58

Protestors reportedly used AirDrop to share anti-government material during China's long and strict COVID-19 lockdowns. Which is why Chinese authorities last week admitted that the use of AirDrop is considered problematic after police previously found inappropriate material being shared on the Beijing subway using the protocol.

Infoseccers think attackers backed by China are behind Ivanti zero-day exploits
2024-01-11 15:06

Security experts believe Chinese nation-state attackers are actively exploiting two zero-day vulnerabilities in security products made by Ivanti. Ivanti believes fewer than ten victims have been successfully attacked thus far, but according to a Shodan scan by Beaumont, the number of vulnerable gateways exposed to the internet is just north of 15,000.

China claims it cracked Apple's AirDrop to find numbers, email addresses
2024-01-09 21:46

A Chinese state-backed research institute claims to have discovered how to decrypt device logs for Apple's AirDrop feature, allowing the government to identify phone numbers or email addresses of those who shared content. China has a long history of censoring its people, requesting Apple block access to mobile apps, blocking encrypted messaging apps, such as Signal, and creating the Great Firewall of China to control what sites can be visited in the country.

Pro-China campaign targeted YouTube with AI avatars
2023-12-18 01:06

Shadow Play advanced six distinct narratives, with two dominant themes: that China is "Winning" a technology war with the US; and the competition for rare earth minerals. Other narratives include that "The US is headed for collapse and its alliance partnerships are fracturing; that China and Russia are responsible, capable players in geopolitics; that the US dollar and the US economy are weak; and that China is highly capable and trusted to deliver massive infrastructure projects," outlined ASPI. Infosys loses fourth senior exec.

China's MIIT Introduces Color-Coded Action Plan for Data Security Incidents
2023-12-16 07:32

China's Ministry of Industry and Information Technology (MIIT) on Friday unveiled draft proposals detailing its plans to tackle data security events in the country using a color-coded system. The...