❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects

22 September 2026 at 14:47

Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday.

The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said.

The timing of the malicious activity mirrors other spikes threat hunters observed and attributed to multiple Chinese espionage threat groups. Yet, Volexity noted UTA0565’s campaigns differed from those attacks by using multiple fake websites to deceive victims.

Volexity shared phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung. The group spoofed domains impersonating the Center for American Progress and China Digital Times in other phishing emails.

While UTA0565 showcased a variance in tactics, it used the same components researchers observed in previous instances of the exploit kit across multiple Chinese threat groups.

“This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese computer network exploitation community, where the core kit was likely shared, customized, and weaponized by multiple groups,” Volexity wrote in the blog post. “The activity reported so far reflects only two organizations’ observations; the full scope and impact are likely far broader.”

The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Sept. 8 in Windows Advanced Local Procedure Call. 

Proofpoint, which previously observed multiple state-aligned threat groups chaining the vulnerabilities together in attacks since last August, said a limited group of organizations were exposed to all three vulnerabilities in a short window. 

Proofpoint previously attributed attacks involving the zero-days to APT31, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket. At the time it warned that attackers of other origins and motivations could strike soon as well.

Volexity said UTA0565 used a payload from a previously undocumented malware family it tracks as “CLEANGULP.” Researchers also found several domains likely used by UTA0565 in similar campaigns targeting media organizations, halal restaurant search websites and corporate training organizations. 

“UTA0565’s use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns observed by Volexity, both in the mechanics of the exploitation and the presentation to end users,” researchers wrote. “Using real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.”

The post Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects appeared first on CyberScoop.

Citing China, President Trump doubles down on hands-off approach to AI regulation

By: djohnson
22 September 2026 at 11:16

President Donald Trump continued to defend his administration’s hands-off approach to AI regulation in the wake of hacks carried out by U.S. commercial frontier models that have rattled policymakers and industry veterans and spurred calls for more regulatory oversight.

In a Truth Social post Monday, Trump dismissed worries from critics that “AI is going to kill us,” comparing them to complaints from environmentalists about climate change, which he also alleged was a false narrative. He also posited that nothing may matter more than future U.S. dominance of the technology over geopolitical rivals like China.

“Whoever wins AI, WINS!” Trump posted. “We are leading now over China, and everyone else, and I’m going to keep it that way! I’m not going to stifle Growth, of something that will be bigger than the Industrial Revolution, or the internet, itself.”

Trump has previously suggested that good leadership is the only regulation the U.S. needs for artificial intelligence. He later claimed the Department of Justice was ready to “rein things in” if companies overstepped, but offered no specifics on enforcement, legal authority, or where he would draw that line.

“We will be careful, and that’s why we have the Department of Justice, and other Law Enforcement bodies, that will rein things in if we have to, but I will only encourage AI or, SI (SUPER INTELLIGENCE)!” Trump concluded.

Secretary of the Treasury Scott Bessent recently told Congress that private lawsuits could force AI companies to institute better security, saying it’s clear what the government “shouldn’t do on safety is to give these labs a liability exemption, which is what they are asking for.”

“The best way to guarantee safety is that the creators are liable for what they build and generate,” Bessent said.

Beyond existential fears, critics also argue that inadequate regulation or cybersecurity controls in current AI systems make them impossible to fully control or monitor.

Recently, former President Barack Obama criticized the argument from Trump administration officials that the free market will naturally push industry toward self-regulation and that “these companies will solve the safety issues because they have every incentive to do so.”

“If it turns out to be dangerous, people will just sue them and they’ll be worried about financial liability,” Obama said last week in remarks at Colgate University in New York. “That’s not how we treat airlines or drug companies or food companies.”

The Trump administration issued an executive order earlier this year that set up a voluntary testing regime for some commercial frontier models, largely at private industry’s discretion. That order was significantly delayed and altered by AI industry boosters to ensure that governmental review did not cause companies to postpone their release timelines for new models.

That agreement did not last long before fast-moving events caused the administration to strike another, non-public agreement with frontier AI companies like OpenAI, Anthropic and others governing pre-release testing for models.

But the Trump administration has consistently argued that regulation will harm, not help, U.S. innovation and global competitiveness, and the threat of China frequently looms large in those discussions.

Experts believe China’s AI models are behind U.S. models at the top of the market, where OpenAI and Anthropic have consistently pushed the frontier limits of model capabilities. But Chinese lower and “middle class” models are often cheaper, more efficient and can even outperform more powerful models because users can dedicate exponentially more tokens for their tasks.

The U.S. government has accused Chinese AI companies of conducting widespread, “systematic” distillation of U.S. frontier models, with the implicit encouragement of Beijing.

In defending the administration’s approach, David Sacks, co-chair of the President’s Council of Advisors on Science & Technology and a top adviser on AI issues, specifically cited the threat from China and other countries that he claimed would not be subject to similar restrictions.

“We’re not the only country that has advanced AI labs, and as the president declared…we have to win this AI race,” Sacks told Politico in May, later adding “I think that’s the first thing to recognize is that if somehow we slow down or stop AI development, it doesn’t mean that AI progress is going to stop. It just means it’s going to happen in other countries and specifically China.”

Some observers have alleged that despite their larger differences, top leaders in the U.S. and China may view AI similarly at the strategic level, specfically that increased adoption – and risks – of AI are inevitable.

Ronan Murphy, director of the tech policy program at the Center for European Policy Analysis, posited that while there may not be a formal agreement between the two countries, “they share views both in Beijing and in Washington, particularly in the White House, of: you have to allow this to happen.”

“Clearly there’s a call for regulation from many quarters of AI in the U.S. and elsewhere, but in the White House – and we heard David Sacks talking about it [recently] – It’s ‘let them cook,’ and the Chinese approach seems to be the same,” said Murphy in a press briefing. “So there might be consensus at that level, if nothing else.”

The post Citing China, President Trump doubles down on hands-off approach to AI regulation appeared first on CyberScoop.

China spy chief points at US AI models in cyber threat warning

15 September 2026 at 08:54
China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.

Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

14 September 2026 at 10:28

China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI.

The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.

AI lets small actors run state-level hacking campaigns, Anthropic report finds

By: Greg Otto
10 September 2026 at 15:45

Artificial intelligence has removed the skill advantage that once set state-sponsored hackers apart from lone criminals, according to a threat report Anthropic published Thursday that documents misuse of its Claude models across seven areas of harm.

The report, which details activity observed between December 2025 and August 2026, covers cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation. Anthropic said it disrupted each operation, strengthened safeguards and shared intelligence with authorities and industry partners where appropriate. 

“The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” the report reads. “We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.”

The cyber operations the company detailed were a Russian-aligned espionage campaign that hit more than 20 government and defense organizations across Ukraine and Europe, two Chinese undergraduates who ran an automated exploit foundry that produced more than a dozen potential zero-days in a single month, affiliates of the ShinyHunters crime collective who dumped 2,100 cloud access tokens across 40 corporate tenants in 34 hours, and a lone hacktivist who targeted European political parties via stolen API keys. 

For decades, cybersecurity researchers and investigators have pointed to sophisticated operations as a signature of state-sponsored tradecraft, while crude intrusions suggested amateurs or petty criminals. Anthropic posits in the report that AI has erased that conventional thinking, especially since a “majority of the operations described in this report were enabled by AI via direct execution or orchestration.”

“For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation,” the report said, adding that a hacktivist on stolen API keys, scattered criminals and a state espionage operator each ran campaigns that a year earlier “would have required many skilled operators and specialist knowledge.”

The most extensive case involved a malicious actor using the handle “JackPoterz” whose actions aligned with Russian state espionage, matching behaviors linked to Midnight Blizzard. 

According to the report, the actor employed a custom toolkit composed of two families of Windows-based implants, a mobile exploitation kit, a credential stealing tool that targets browser password stores, a phishing platform designed to mimic priority targets like government organizations, and an administrative console used to manage compromised accounts. Targets included military intelligence bodies in Ukrainian and European governments, diplomatic and defense organizations, and people connected to U.S. foreign policy.

According to the report, AI monitored whether security products flagged the actor’s malware. When a detection occurred, “agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections,” the report said.

The same actor bulk-exported mailboxes at drone component manufacturers and stole a complete software development kit for a drone vision system, then spent days recovering its architecture and details of an unannounced product. The actor also compromised hotel Wi-Fi vendors to reach guests through DNS hijacking, took over WhatsApp accounts with headless browsers, and stole more than 300,000 national identity records from a North African government agency, along with registry data on more than half a million companies.

The Chinese-speaking operators, which the company says were partly carried out by undergraduates at a Chinese university, put Claude to work on vulnerability research around the clock. One workflow iterating on network appliance firmware “yielded more than a dozen possible zero day findings in a single month.” It ran “agent swarms,” in which a lead agent divided work among parallel subagents, and kept campaign memory between sessions. 

Clusters linked to ShinyHunters showed how AI shortens criminal timelines. One supply-chain breach ended with a dump of more than 2,100 Azure access tokens spanning more than 40 corporate tenants in about 34 hours. “AI agents performed nearly all of the work,” the report said. Another compromise moved from a single stolen developer token to full control of a victim’s cloud environment in roughly three hours.

The report also has a section dedicated to distillation attacks that Anthropic claims were carried out since February by seven labs based in China, including Alibaba, DeepSeek, Moonshot AI, Xiaomi and Zhipu. Operators affiliated with Alibaba ran the largest attack Anthropic has measured, peaking “at nearly 3 million exchanges per day launched from more than 3,500 fraudulent accounts” to harvest the outputs of Claude Opus models for training its Qwen systems.

The outputs were culled from users who never knew they were involved. The report said Moonshot and DeepSeek silently forwarded their own customers’ requests to Claude and returned its answers as their own, exposing data users had not agreed to share, including surveillance footage of a tracked individual pulled by a user likely affiliated with the People’s Liberation Army. Those practices are “likely inconsistent with privacy laws and the labs’ own terms of service,” the report said.

Earlier this week, a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI accused Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities.

Anthropic said it published the cases to give outsiders a view of how these threats form, framing the disclosures as an early look at a shifting landscape. 

“As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer,” the report said. The old idea of “security through obscurity,” it added, “is no longer viable in this new AI-assisted world: everything connected to the internet is a potential target for exploitation.”

You can read the full report on Anthropic’s website.

The post AI lets small actors run state-level hacking campaigns, Anthropic report finds appeared first on CyberScoop.

Governments ‘buying time’ in race between innovation, security, national cyber director says

10 September 2026 at 09:53

The United States and allied governments are “buying time for our systems to become more secure” as artificial intelligence advances and spreads, National Cyber Director Sean Cairncross said Thursday.

“That is a big deal to be ahead of this, to be ahead of this race, and because it’s an exponential  equation,” he said at the Billington CyberSecurity Summit. “Once you fall behind, it is much more difficult to make it up, and so that is the context in which all this is taking place. We are trying to balance the innovation side of running at speed with securing our systems and handling this technology responsibly, which is to say, not letting it fall into the hands of people who would do us harm, our adversaries.”

Earlier this week, U.S. security agencies accused Chinese AI companies of trying to illegally distill U.S. frontier AI models. Also this week, Anthropic disclosed a fourth AI hacking incident where one of its models broke into third-party systems.

“We all face the same threat picture, and it’s vital that we’re working closely together to secure those systems before that technological cycle catches up on the back end,” Cairncross said.

AI has further exposed long-standing cybersecurity problems that have gone unaddressed, he said.

“In AI development, particularly on the vulnerability discovery side and the coding side, it hasn’t created a new set of problems,” Cairncross said. “What it’s done is it’s dragged to the surface problems that have been latent in this space for decades. There’s been under-resourcing and deprioritization of basic cyber hygiene and cybersecurity.”

Cairncross’s messages echoed those of other Trump administration cyber officials speaking this week at the summit.

A top FBI official, Jason Bilnoski, said the solutions to the difficulties AI poses aren’t new; basic cyber hygiene is key.

And the director of the Cybersecurity and Infrastructure Security Agency, Nick Andersen, said historical neglect of cybersecurity fundamentals poses a serious threat that requires a speedy answer.

“We know the worst that can happen, and if we don’t make some very serious, very significant changes in quick succession … you all are going to have to go home and look your family, look your friends in the eye and explain to them how you knew the worst that could happen and why we didn’t do enough,” he said.

The post Governments ‘buying time’ in race between innovation, security, national cyber director says appeared first on CyberScoop.

Chinese espionage groups swarm to exploit triple-link chain of zero-days

9 September 2026 at 17:17

Proofpoint researchers have spotted at least four state-aligned threat groups chain a trio of zero-day vulnerabilities to conduct espionage on various targets of interest to China’s government since late August. 

The Chinese espionage group that Proofpoint tracks as TA412, also known as Violet Typhoon and APT31, struck first, exploiting the chain of vulnerabilities Aug. 28. At least three additional espionage threat groups followed suit, exploiting the same vulnerabilities in subsequent waves of attacks days later, researchers said.

The exploit chain Proofpoint calls BlueMoon targets Chrome, Chromium-based browsers and Microsoft Windows. It allows attackers to run code in the browser’s sandbox, escape the sandbox and gain system privileges to access a targeted machine, said Mark Kelly, staff threat researcher at Proofpoint.

“All three vulnerabilities were exploited before patches were available to the public,” he said.

The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Tuesday in Windows Advanced Local Procedure Call. 

“While the V8 vulnerabilities were known and fixed in Chromium source code, they were not yet patched in the latest publicly available browsers at the time of the activity, meaning they effectively functioned as zero-days in those products,” Kelly said.

Proofpoint said the exploit kit developer likely reverse engineered the publicly available Chromium patches to weaponize the browser exploit chain during that gap.

With a limited group of organizations exposed to all three vulnerabilities, attackers moved quickly and likely rushed development to target a narrow pool of potential targets. “In all observed cases, the infrastructure used for exploit delivery was created on the same day as — or in the days immediately preceding — the associated campaigns,” Proofpoint wrote in a threat intelligence report.

APT31, a group that’s committed espionage on behalf of China’s Ministry of State Security, including seven Chinese nationals indicted by the Justice Department in 2024, dropped various lures containing the exploit chain loader in phishing emails targeting non-governmental organizations, mining companies and commodity trading firms in the United States. 

The phishing link installed a malicious browser extension disguised as Google Gemini on targeted machines, enabling attackers to surveil browser activity, steal credentials and execute commands, according to Proofpoint. 

Other distinct threat groups have also used the BlueMoon exploit chain with some slight technical changes and variances in targeting. 

“Proofpoint observed BlueMoon usage as recently as Sept. 8,” Kelly said. “The activity peaked Sept. 2-3 immediately prior to the Chrome patch being released and has continued intermittently since then.”

A China-aligned espionage threat group Proofpoint tracks as UNK_LateNight targeted multiple U.S. aerospace companies Sept. 2. Researchers also that day observed UNK_DoubleCheck, a suspected espionage-motivated threat group targeting Vietnamese manufacturing organizations with emails from a compromised Southeast Asian government account. 

Researchers said UNK_QuietRacket, another espionage group aligned with China, targeted government, consulting and financial sector organizations in Indonesia and Singapore Sept. 3.

Proofpoint has directly observed fewer than 20 organizations targeted globally thus far, but Kelly said the true number of impacted organizations is likely much higher. 

While Proofpoint attributes most of the observed attacks to Chinese espionage groups, attackers of other origins and motivations could strike soon as well. 

“Given its ease of adoption, we expect the exploit kit is likely to proliferate further and be adopted by additional espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers,” Kelly said.

The post Chinese espionage groups swarm to exploit triple-link chain of zero-days appeared first on CyberScoop.

FBI cyber chief worries private sector not sharing enough cyber threat information

9 September 2026 at 11:05

The private sector still isn’t sharing enough cyber information with the FBI in part because organizations are operating on false assumptions about what the bureau will do with what it collects, the FBI’s top cyber official said Wednesday.

Brett Leatherman, assistant director of the FBI’s cyber division, said in remarks at the Billington CyberSecurity Summit and in a discussion with reporters that organizations stand to benefit from bringing in the bureau when it’s compromised by hackers from the People’s Republic of China (PRC) and others. But one of the “key misconceptions” is that “the FBI is somehow sharing information with regulators for regulatory purposes, and that’s not the case.”

“From my standpoint over the last few years, I think we’ve seen a hesitancy on some companies to engage [with the] FBI,” Leatherman said.

“It worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own,” he said. “That should worry all of us when that happens, because who is positioned to eradicate the PRC from their environments as quickly as when they might have law enforcement or the intelligence teams at FBI come in and actually help with that effort?”

In response, the bureau has held events like outside counsel summits to walk attorneys through what the FBI offers victims during a major breach, Leatherman said. The FBI also has adjusted its standards for when to share information about threats when weighing how much it might help victims versus whether it might jeopardize a law enforcement operation in the future.

“Our posture is, ‘Share until it hurts,’” he said. “What I always ask my team is, if the victim were sitting in this room right now … would they want this information, and what is the compelling justification we have to not share this now to stop the impact versus taking an operation 90 days from now?”

“We have to in every situation where we have intelligence, we have to take that victim perspective because they can’t voice it in that moment,” he said. “Where we can share in a way that will protect our equities in conducting those operations, we’ll do it. But [where] we can have an impact to hundreds of pieces of critical infrastructure, we should share that, and we should share it quickly.”

The FBI published a new cyber strategy Wednesday that places an emphasis on aiding victims of cyberattacks. Helping victims also helps investigations, Leatherman said.

“We used to look at remediation and incident response as mutually exclusive to investigation and threat pursuit,” he said. “And what we’ve shown over the last few years is that they are not mutually exclusive. … If we can work with victims in a way that preserves investigative information, that allows us to move upstream against the actors.”

The post FBI cyber chief worries private sector not sharing enough cyber threat information appeared first on CyberScoop.

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

9 September 2026 at 08:32

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.

Feds accuse China of ‘systematic’ distillation of U.S. AI models

By: djohnson
8 September 2026 at 16:47

 The U.S. government is accusing Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities. 

According to a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI, the sheer scale of these efforts since 2024 indicate that distillation is a critical part of China’s AI industrial policy.

“China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy,” the agencies wrote. 

The advisory names Chinese companies like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, saying they spent billions of tokens across millions of exchanges and requests with frontier U.S. AI models like Anthropic’s Claude, OpenAI’s ChatGPT, Google Gemini, and xAI’s Grok, since at least late 2024.

The U.S. agencies said the companies used data culled from these interactions to strengthen their own domestic models, a practice that is tacitly encouraged but not directed by political leaders in Beijing.

DeepSeek, for example, distilled frontier U.S. models to generate synthetic training data for its R1 and R3 models, including four different versions of Claude, two versions of Gemini, five versions of ChatGPT and Grok 4. Those models helped train DeepSeek’s capabilities in areas like agentic functioning, question and answer optimization, creative and occupational writing and others.

Another Chinese company, Moonshot AI, allegedly distilled 18 different U.S. models – including Fable 5, Anthropic’s current, most advanced commercially available model – to train its Kimi-K2 and Kimi K3 models. The company used millions of queries meant to extract enhanced capabilities in areas like agentic reasoning, coding and data analysis, computer vision, larger logical frameworks, visual processing and others.

Chinese AI companies manage a sophisticated set of tools and systems that route requests and prompts through multiple pathways to avoid detection.

The advisory lists common tactics observed by Chinese companies, including spreading requests across different accounts, models and platforms, using native APIs, remote cloud providers, and third-party aggregators to obfuscate user metadata, and leveraging proxies and gray tech markets to get around geographic restrictions, terms of use and safeguards built into frontier models.

“Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the advisory stated.

For decades, U.S. national security officials and western business leaders have accused China of leveraging cyberattacks, insider threats and other forms of economic espionage to pilfer proprietary or sensitive technologies from U.S. businesses.

In June, Michael Kratsios, White House head of Office of Science and Technology Policy, made a similar accusation about MoonshotAI of distilling Fable 5 to train its own models, and described a similar “sophisticated” system for evading guardrails and restrictions on usage.

The warning Tuesday levies similar charges about Chinese theft of American tech, but for frontier AI companies that are facing lawsuits themselves from artists, authors, media organizations and other parties who say AI companies illegally trained their models on copyrighted or trademarked work.

Even within the competitive AI industry, companies and open-source organizations commonly share weights and measures for AI systems, or distill other AI systems in the course of legitimate work or research.

The agencies acknowledge this reality, but claim that Chinese companies are engaged in “aggressive, malicious, and targeted distillation activities at an industrial scale.”

The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop.

Wyden seeks upgraded NSA security guidance on commercial VPN use

2 September 2026 at 11:00

Sen. Ron Wyden, D-Ore., is asking the National Security Agency to update public guidance on the security risks associated with commercial virtual private networks, and to answer questions about foreign surveillance threats against standard VPNs.

In a letter to NSA Director Gen. Joshua Rudd that Wyden sent Wednesday, the senator continued his push to warn about standard, commercial VPNs, following letters to federal agency leaders in March and July.

“While commercial Virtual Private Networks (VPNs) are recommended by federal agencies and widely marketed as shields against online spying, standard consumer VPNs do not sufficiently protect users from sophisticated adversaries,” Wyden wrote in the letter, first reported by CyberScoop. “Other, more secure alternatives are widely available.”

Wyden took aim at “single-hop” VPNs that routes data through one server before arriving at the destination.

He cited a Congressional Research Service paper from last month that said “a single-hop VPN, however strongly encrypted, offers essentially no protection against an adversary who can compel… or infiltrate that one provider,” compared to “multi-hop and mixnet architectures [that] directly target and mitigate this weakness” since a second server only knows the IP address of the first server.

He also cited a letter responding to an earlier missive that Wyden signed with other lawmakers in an exchange with the Office of the Director of National Intelligence. The office offered a note of caution about scrutinizing VPN providers’ privacy and security policies, but Wyden said “it overlooked the importance of the VPN service’s architecture against sophisticated foreign threats.”

Wyden referenced an advisory from the NSA and allied foreign governments last September about a China-sponsored campaign to target telecommunications, government and military networks.

He said that the NSA should update its public guidance on VPN configuration.

“Americans facing advanced foreign threats — including government personnel, defense contractors, journalists, and human rights defenders — deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries. 

He also asked Rudd to answer a series of questions in an unclassified reply. Some view single-hop commercial VPNs as sufficient for average internet users, and Wyden asked whether they were strong enough to protect “Americans’ sensitive digital footprints against foreign adversaries capable of monitoring internet backbones.”

And Wyden wants Rudd to weigh in on the importance and effectiveness of multi-hop anti-surveillance systems, like Apple Private Relay, Tor and Nym, as well as how multi-hop proxy systems fare against mixnet architectures.

You can read the full letter below.

The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop.

Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

28 August 2026 at 06:30

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

The post Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says appeared first on SecurityWeek.

Is China Secretly Fueling America's Data Center Rage?

By: BeauHD
28 August 2026 at 23:30
alternative_right shares a report from Axios: Roughly 200 accounts from a suspected Chinese bot farm have quietly tried to influence Americans to oppose AI data centers on social media, X said Thursday night. The X Safety team probed suspected Chinese accounts involved in influence operations and identified 200,000 accounts, including 200 accounts "posting in a manner that could manipulate a legitimate debate about American AI and energy policy," the team said in a tweet. The posts included content on how AI strains the electricity grid and increases utility prices and "cartoons that depicted data-center operators enriching themselves at the public's expense." It's unclear what, if any, action X will take to suspend or delete accounts from the bot farm. One of the reports mentioned in the article estimates that opposition campaigns have delayed or obstructed roughly $45.8 billion in data center projects in Virginia alone. Jim Prosser, a former Twitter communications executive, pushed back on Silicon Valley claims that opposition to data centers is a "Chinese psyop," arguing that Big Tech is using the label to dismiss legitimate local concerns. "If you can get both Greg Abbott and Kathy Hochul agreeing on something, it's probably not a Chinese psyop," he told Axios. Prosser said the industry needs to spend more time listening to affected communities rather than dismissing them from afar: "If you're a [venture capitalist] in Atherton or Menlo Park opining about how somebody in Ohio should feel, and you've never been to Ohio, that's a problem."

Read more of this story at Slashdot.

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

26 August 2026 at 17:38

Citing cyber and other security threats, President Donald Trump signed an executive order Wednesday that declares a national emergency to secure the U.S. bulk-power system and aims to prohibit certain foreign-produced equipment, software and systems from being used in the  country.

The order says it forbids “any acquisition, importation, transfer, or installation” of such foreign-produced equipment if it’s determined to pose a significant national security risk.

“To deal with the threat to the national security, foreign policy, and economy of the United States, the Order, among other things, generally prohibits certain foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities that could pose cybersecurity or operational risks, from being purchased or installed in the United States, or appropriately conditions such purchases and installations to address those risks,” the White House said in a fact sheet.

The executive order is a response to fears of Chinese-made equipment housed within U.S. energy infrastructure, and a continuation of other measures from the Trump administration to shun that equipment.

The order, “Declaring a National Energy Emergency to Secure the United States Bulk-Power System,” cites “malicious cyber activities” as one impetus.

“The minimal restrictions on acquisition or operation in the United States of foreign-produced bulk-power system electric equipment augment the ability of some foreign entities to create and exploit vulnerabilities in such equipment; for instance, such equipment might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely,” it states.

China supplies 85% of solar supply chain production capacity, according to the International Atomic Energy Agency, and China is a major player in the power transformer manufacturing business.

In 2024, then-FBI Director Christopehr Wray told Congress that hackers prepositioning themselves in small office and home routers had the electricity grid as one of their targets should China and the United States go to war.

Near the end of Trump’s first term he also signed an executive order seeking to limit the purchase of foreign-made bulk-power equipment. The Biden administration suspended that order, citing the need to review its scope, and revoked and replaced a related Energy Department order. Some utilities found compliance with the 2020 executive order difficult.

For the new order, the Energy Department has 120 days to develop rules to implement the order, in consultation with other key departments.

The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.

Officials disrupt Chinese espionage operation that hit multiple federal agencies

26 August 2026 at 15:35

Federal authorities Wednesday revealed a multi-layered Chinese state-sponsored espionage operation that’s targeted and compromised U.S. critical infrastructure, including multiple federal agencies, since 2018. 

Officials seized domains and unsealed an affidavit detailing how a Chinese government-funded front company assembled a botnet and complementary systems that allowed attackers to intrude highly sensitive networks.

The FBI and Justice Department said the state-sponsored group, known as “QTFY,” has targeted and intruded the networks of the Departments of Energy, Justice, Health and Human Services, the Federal Reserve, NASA, National Institutes of Health, and, unsuccessfully in March, the Senate. 

Financial institutions, defense contractors, utility companies, telecom providers and hospitals have also been targeted by the threat group, which includes former members of China’s military, according to court records. 

Officials said QTFY also attempted, but was unsuccessful, in gaining access to a U.S. election system in June. 

The long-running operation, which officials obstructed by seizing malicious infrastructure, provided an expansive set of services. QTFY’s full hacking suite allowed attackers to scan and exploit vulnerabilities, infect IoT devices for a botnet, and conceal or reroute traffic.

QTFY’s operation was comprehensive with features that provided continuous reconnaissance capabilities and flexibilities designed for specific targets or objectives, said Ryan English, information security engineer at Lumen Technologies’ Black Lotus Labs, which aided the disruption efforts. 

Officials said they seized three domains, which cut off access to QScan and QTRouter, the group’s primary platforms. 

“Today’s announcement demonstrates the Justice Department’s steadfast commitment to going on the offensive against cyber threats to national security,” John A. Eisenberg, assistant attorney general for national security, said in a statement. “These court-authorized seizures deny People’s Republic of China-linked hackers access to tools they use to mount online attacks against our nation’s critical infrastructure.”

The FBI, National Security Agency and Cyber National Mission Force released a joint cybersecurity advisory with QTFY’s known indicators of compromise Wednesday. Officials also detailed the China-linked hacking group’s affiliations and collaborations with other state-sponsored groups.

QTFY targeted sensitive networks in the U.S. and globally by exploiting vulnerabilities in multiple vendors’ products, including Pulse Secure, Fortinet, Citrix, Microsoft, F5, Kentico CMS, Atlassian Confluence, Ivanti, Check Point, CrushFTP and BeyondTrust, officials said.

QScan, the reconnaissance and vulnerability scanning tool, included more than 200 proof-of-concept exploits, according to court records. 

“It was designed for large-scale deployment. On a single day in 2024 for example, QScan processed over two million scanning and exploit tasks,” a special agent for the FBI said in the affidavit.

The Chinese hacking collective exploited multiple Ivanti zero-day vulnerabilities in September 2024 to intrude the networks of three DOE national laboratories, NIH, an HHS agency and a U.S.-based security device manufacturer. Officials said the seized domains were all used in those attacks. 

The FBI has been investigating QTFY, which operated out of a private China-based front company, Nanjing Xinjiuwei Network Technology Company, since at least 2019. The group has been consistently active for more than eight years. 

“Discovery of these private companies building networks for China is becoming more frequent,” English said. “We’re starting to see that when they’re getting exposed, some of these have been in business a few years before they’re found.”

The takedown follows a series of technical operations aimed at dismantling China state-sponsored attackers’ infrastructure, including an operation in early 2025 that allowed officials to remove PlugX malware from thousands of U.S.-based computers.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” Attorney General Todd Blanche said in a statement. “We are here to ensure security for the American people and will use every tool we have to keep that promise.”

The post Officials disrupt Chinese espionage operation that hit multiple federal agencies appeared first on CyberScoop.

❌
❌