VMware Zero-Day Under Attack By China-Linked Hackers Since October 2024 post, september 30, 2025oktober 3, 2025 Broadcom has published security advisory VMSA-2025-0015, disclosing six vulnerabilities in VMware products — among them four rated High / Important — and urging users to apply patches immediately. One of the more serious flaws is CVE-2025-41244, a local privilege escalation vulnerability (CVSS score 7.8) Continue Reading
People’s Republic Of China (PRC) Breach US Nuclear Weapons Agency (NNSA) In Historic SharePoint Exploit Attacks post, juli 23, 2025juli 24, 2025 Threat Actors, linked to the People’s Republic of China (PRC) have breached the National Nuclear Security Administration (NNSA) by exploiting a recently patched critical zero-day vulnerability chain in Microsoft SharePoint, a platform commonly used across industries to host internal files and websites. NNSA is the U.S. agency responsible for overseeing… Continue Reading
Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks post, juli 21, 2025juli 23, 2025 Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in “ToolShell” attacks. In May, during the Berlin Pwn2Own hacking contest, researchers exploited a zero-day vulnerability chain called “ToolShell,” which enabled them to achieve remote code execution in Microsoft SharePoint. These… Continue Reading
Global hack on Microsoft product hits U.S., state agencies, researchers say post, juli 20, 2025juli 21, 2025 Unknown attackers exploited a “significant vulnerability” in Microsoft’s SharePoint collaboration software, hitting targets around the world. Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching U.S. federal and state agencies, universities,… Continue Reading
National Guard hacked by Chinese ‘Salt Typhoon’ campaign for nearly a year, DHS memo says post, juli 15, 2025juli 24, 2025 An elite Chinese cyberspy group hacked at least one state’s National Guard network for nearly a year, the Department of Defense has found. The hackers, already responsible for one of the most expansive cyberespionage campaigns against the U.S. to date, are alleged to have burrowed even further than previously known… Continue Reading
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms post, juli 3, 2025 The French cybersecurity agency on Tuesday revealed that a number of entities spanning governmental, telecommunications, media, finance, and transport sectors in the country were impacted by a malicious campaign undertaken by a Chinese hacking group by weaponizing several zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices. The campaign, detected… Continue Reading
China-linked Salt Typhoon Exploits Critical Cisco Vulnerability to Target Canadian Telecom post, juni 24, 2025 The Canadian Centre for Cyber Security and the U.S. Federal Bureau of Investigation (FBI) have issued an advisory warning of cyber attacks mounted by the China-linked Salt Typhoon actors to breach major global telecommunications providers as part of a cyber espionage campaign. The attackers exploited a critical Cisco IOS XE software (CVE-2023-20198, CVSS score:… Continue Reading
China Is Studying How to Hack and Crash Our Power Grids post, juni 19, 2025juni 23, 2025 Over the past several weeks, I’ve been conducting a large-scale bibliometric study on publicly available Chinese academic literature related to hacking and crashing Western power grids. In this article, I’m sharing the main findings of that study. EDIT (20.6.2025, 8:54 CET): All of the Chinese academic articles I examined are… Continue Reading
Over 70 Organizations Across Multiple Sectors Targeted by China-Linked Cyber Espionage Group post, juni 9, 2025juni 10, 2025 The reconnaissance activity targeting American cybersecurity company SentinelOne was part of a broader set of partially-related intrusions into several targets between July 2024 and March 2025. “The victimology includes a South Asian government entity, a European media organization, and more than 70 organizations across a wide range of sectors,” SentinelOne… Continue Reading
Tsjechië: China zit achter cyberaanval op ministerie van Buitenlandse Zaken post, mei 28, 2025juli 3, 2025 Tsjechië houdt een Chinese groep hackers verantwoordelijk voor een cyberaanval op het ministerie van Buitenlandse Zaken. Volgens de Tsjechen gaat het om een “kwaadaardige cybercampagne”, gericht op een netwerk dat gebruikt werd voor niet-geheime communicatie. Het land stelt dat de aan China gelinkte groep APT31 daar vermoedelijk achter zit. Die… Continue Reading