#ChineseHackers
Well hey, did you have #ChineseHackers spying on your #Xfinity use on your bingo board?
Special Report: Chinese government-backed hackers have penetrated deep into U.S. internet service providers in recent months to spy on their users, according to people familiar with the ongoing American response and private security researchers.
Chinese government hackers penetrate U.S. internet providers to spy
Beijing’s hacking effort has “dramatically stepped up from where it used to be,” says former top U.S cybersecurity official.
www.washingtonpost.com
August 27, 2024 at 2:10 PM
📰 Hacker Berbahasa Mandarin Eksploitasi WordPress dan Zyxel untuk Curi Data Pemerintah

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/23/hacker-china-eksploit-wordpress-zyxel-curi-data-pemerintah/

#c2 #chineseHackers #chineseThreatActor #cve-2023-54391 #cve-2026-34908 #cve-202
September 23, 2026 at 5:50 AM
Chinese hackers used AI agents to autonomously breach Taiwanese government systems, marking a new era in cyber warfare. #CyberSecurity #AI #CyberAttack #Taiwan #ChineseHackers #AIWarfare https://thedailytechfeed.com/chinese-hackers-use-ai-agents-in-unprecedented-attack-on-taiwan/
August 12, 2026 at 4:57 PM
🚨 Chinese hackers have infiltrated Microsoft SharePoint in a stealth APT attack—targeting agencies & enterprises worldwide. What does this mean for cloud security?
#Cybersecurity #SharePointBreach #APT #CloudSecurity #InfoSec #ChineseHackers

thecyberlens.com/p/chinese-ha...
Chinese Hackers Infiltrated SharePoint and What It Means for Enterprise Security
Inside the Advanced Persistent Threat That Compromised Microsoft SharePoint—and the Cybersecurity Oversight That Made It Possible
thecyberlens.com
July 22, 2025 at 11:50 PM
Chinese Hackers Exploit ZyXEL Switch Flaw to Steal Data From Nearly 1,000 Devices #ChineseHackers #CriticalFlaws #DataBreach
Chinese Hackers Exploit ZyXEL Switch Flaw to Steal Data From Nearly 1,000 Devices
 A Chinese threat actor has been using the recently discovered vulnerability in ZyXEL GS1900 switches to steal crucial information from the devices around the world, according to GreyNoise, a threat intelligence company. The vulnerability, tracked as CVE-2026-7273, has a CVSS score of 8.8 and is a stack-based buffer overflow, enabling a remote unauthenticated attacker to execute OS commands via a specially crafted HTTP request.  ZyXEL has issued security updates for ten GS1900 switch models in June. However, according to GreyNoise, the flaw was actively exploited in August, targeting the devices in 48 countries. The threat actors used a Python script, which was significantly obfuscated to hide its purpose, to extract the hashes of the root credentials, configuration, and network information from 996 affected switches.  While the script targeted the GS1900-24 switches with firmware versions 2.10 to 2.90, some of the command-line options in the script contained values related to libc base addresses and global offsets. Therefore, it might be possible that the threat actors could use the same vulnerability to target other firmware versions. The information stolen from the switches also showed that 564 devices were using default credentials. This lets the attackers effortlessly compromise these devices.  On Monday, the US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog. Also, per the Binding Operational Directive 26-04, all federal agencies must remediate this issue within 3 days of its publication. GreyNoise also reported that the same threat actor conducted Ubiquiti attacks, which involved exploiting the zero-day flaws to gain remote access and execute arbitrary code in the devices.  In addition, the attackers used exploits targeting WordPress flaws to launch attacks against small businesses and government entities in July. The attacks entailed a threat actor compromising a Western government organization, stealing over 18000 sensitive documents from the agency’s backend database, and publishing the results on a Matrix communication service.  However, the cybersecurity firm is yet to confirm if any of these attacks were conducted by the same threat actor. Acronis, another cybersecurity firm, previously identified threat actors using the Red Heron hacking group, which primarily used Gitea’s zero-day flaw to target more than 100 organizations worldwide.
dlvr.it
September 23, 2026 at 12:43 PM
Hacker affiliated with Chinese government targeted US treasury , most crucial official documents in major incident

Tap the link in the bio to explore more

#GLT #news #chinesehackers #usa #usatoday ##worldnews #bbcnews #usa_tiktok
December 31, 2024 at 6:34 AM
“Google Mandiant security analysts, who believe UNC5174 is a contractor for China's Ministry of State Security (MSS), have observed the threat actor selling access to networks of U.S. defense contractors …”

🚨
#UNC5174
#ChineseMalware
#ChineseHackers
September 30, 2025 at 3:34 PM
Washington – Chinese hackers remotely accessed several U.S. Treasury Department workstations and unclassified documents after compromising a third-party software service provider, the agency said Monday.


The department did not provide details on how… #CyberSecurity #ChineseHackers #DataBreach
Treasury says Chinese hackers remotely accessed workstations, documents in 'major' cyber incident
Washington – Chinese hackers remotely accessed several U.S. Treasury Department workstations and unclassified documents after compromising a third-party software service provider, the agency said Monday. The department did not provide details on how…
detne.ws
December 31, 2024 at 3:31 AM
Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool reconbee.com/chinese-hack...

#chinesehackers #IPv6 #Aitmattack #spellbinder #CyberSecurity
Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool
modular backdoor known as WizardNet read more about Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool
reconbee.com
April 30, 2025 at 5:53 PM
📣 New Podcast! "Chinese Hackers Use AI Agents in Multi-Country Cyberattacks: The Rise of AI-Powered Cyber Espionage" on @Spreaker #aiagents #aicybersecurity #aihacking #aisecurity #apt #chinacyberthreat #chinesehackers #claude #cyberattack #cyberespionage #cybersecurity #cyberwarfare #deepseek
Chinese Hackers Use AI Agents in Multi-Country Cyberattacks: The Rise of AI-Powered Cyber Espionage
https://www.osintinvestigate.com A new China-linked cyber campaign shows how AI agents are becoming operational tools for cyber espionage. The SecFlow framework reportedly connected commercial AI models such as Claude, Qwen, and DeepSeek to reconnaissance, exploitation, credential testing, data collection, and reporting. Targets included government, education, political, and industrial organizations across Asia. This episode explores how attackers are combining traditional hacking techniques with AI-driven automation, why exposed infrastructure helped researchers uncover the operation, and what this evolution means for cybersecurity defenders.
www.spreaker.com
September 8, 2026 at 3:00 PM