Security News

US and allies finger China in Microsoft Exchange hack
2021-07-19 18:36

The US has also blamed hackers working with China for ransomware attacks, extortion, crypto-jacking and other cybercrimes. The United States and several allies have officially pointed the finger at China for the recent hack of Microsoft Exchange server as well as an ongoing series of cyberattacks carried out by contract hackers for personal profit.

U.S., Allies Officially Accuse China of Microsoft Exchange Attacks
2021-07-19 13:44

The United States and its allies have officially attributed the Microsoft Exchange server attacks disclosed in early March to hackers affiliated with the Chinese government. In a statement, the White House accused China of using "Criminal contract hackers" to conduct cyber operations.

China's New Law Requires Vendors to Report Zero-Day Bugs to Government
2021-07-19 12:05

The Cyberspace Administration of China has issued new stricter vulnerability disclosure regulations that mandate software and networking vendors affected with critical flaws to mandatorily disclose them first-hand to the government authorities within two days of filing a report. The "Regulations on the Management of Network Product Security Vulnerability" are expected to go into effect starting September 1, 2021, and aim to standardize the discovery, reporting, repair, and release of security vulnerabilities and prevent security risks.

US and allies officially accuse China of Microsoft Exchange attacks
2021-07-19 11:49

US and allies, including the European Union, the United Kingdom, and NATO, are officially blaming China for this year's widespread Microsoft Exchange hacking campaign. The Biden administration attributes "With a high degree of confidence that malicious cyber actors affiliated with PRC's MSS conducted cyber espionage operations utilizing the zero-day vulnerabilities in Microsoft Exchange Server disclosed in early March 2021.".

China's Cyberspies Targeting Southeast Asian Government Entities
2021-07-15 05:57

Russian cybersecurity firm Kaspersky, which first spotted the infections in October 2020, attributed them to a threat actor it tracks as "LuminousMoth," which it connected with medium to high confidence to a Chinese state-sponsored hacking group called HoneyMyte or Mustang Panda, given its observed victimology, tactics, and procedures. About 100 affected victims have been identified in Myanmar, while the number of victims jumped to nearly 1,400 in the Philippines, although the researchers noted that the actual targets were only a fraction of the initial numbers, including government entities located both within the two countries and abroad. The goal of the attacks is to affect a wide perimeter of targets with the aim of hitting a select few that are of strategic interest, researchers Mark Lechtik, Paul Rascagneres, and Aseel Kayal said.

So nice of China to put all of its network zero-day vulns in one giant database no one will think to break into
2021-07-15 01:07

Chinese makers of network software and hardware must alert Beijing within two days of learning of a security vulnerability in their products under rules coming into force in China this year. Though the rules are a little ambiguous in places, judging from the spirit of them, they throw a spanner in the works for Chinese researchers who work with, or hope to work with, zero-day vulnerability brokers.

China Taking Control of Zero-Day Exploits
2021-07-14 11:04

China is making sure that all newly discovered zero-day exploits are disclosed to the government. Under the new rules, anyone in China who finds a vulnerability must tell the government, which will decide what repairs to make.

Hong Kong working to share its digital IDs with mainland China
2021-07-14 08:03

Hong Kong's Office of the Government Chief Information Officer has revealed that the territory is investigating the use of its digital ID in mainland China. In a Q&A, Secretary for Innovation and Technology, Mr Alfred Sit, said "The OGCIO is exploring with relevant authorities in the Mainland and Macao the collaboration opportunities between their identity authentication systems and iAM Smart."

Citing cross-border data transfer and privacy concerns, China promises security blitz on securities
2021-07-07 07:00

Infosec concerns have led China's government to apply closer scrutiny to Chinese companies that list and send data offshore, according to a document written by China's State Council cabinet and the Communist Party's General Secretary. "For a long time, the low cost of illegal securities has plagued the development of the market," states the Opinions on Strictly Cracking Down on Illegal Securities Activities in Accordance with the Law document in state-sponsored Xinhua News.

Combating China's Insider Threat: Can New Laws Curb IP Theft by Foreign Spies?
2021-07-06 12:08

Theft of U.S. IP is a fundamental part of China's stated intention to be the world leader in science and technology by 2050. The Safeguarding American Innovation Act is designed to prevent foreign powers - and especially China - from stealing or unlawfully acquiring U.S. federally funded research.