Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Tag: China

VMware Zero-Day Under Attack By China-Linked Hackers Since October 2024

post, september 30, 2025oktober 3, 2025

Broadcom has published security advisory VMSA-2025-0015, disclosing six vulnerabilities in VMware products — among them four rated High / Important — and urging users to apply patches immediately. One of the more serious flaws is CVE-2025-41244, a local privilege escalation vulnerability (CVSS score 7.8)

Continue Reading

People’s Republic Of China (PRC) Breach US Nuclear Weapons Agency (NNSA) In Historic SharePoint Exploit Attacks

post, juli 23, 2025juli 24, 2025

Threat Actors, linked to the People’s Republic of China (PRC) have breached the National Nuclear Security Administration (NNSA) by exploiting a recently patched critical zero-day vulnerability chain in Microsoft SharePoint, a platform commonly used across industries to host internal files and websites. NNSA is the U.S. agency responsible for overseeing…

Continue Reading

Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks

post, juli 21, 2025juli 23, 2025

Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in “ToolShell” attacks. In May, during the Berlin Pwn2Own hacking contest, researchers exploited a zero-day vulnerability chain called “ToolShell,” which enabled them to achieve remote code execution in Microsoft SharePoint. These…

Continue Reading

Global hack on Microsoft product hits U.S., state agencies, researchers say

post, juli 20, 2025juli 21, 2025

Unknown attackers exploited a “significant vulnerability” in Microsoft’s SharePoint collaboration software, hitting targets around the world. Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching U.S. federal and state agencies, universities,…

Continue Reading

National Guard hacked by Chinese ‘Salt Typhoon’ campaign for nearly a year, DHS memo says

post, juli 15, 2025juli 24, 2025

An elite Chinese cyberspy group hacked at least one state’s National Guard network for nearly a year, the Department of Defense has found. The hackers, already responsible for one of the most expansive cyberespionage campaigns against the U.S. to date, are alleged to have burrowed even further than previously known…

Continue Reading

Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms

post, juli 3, 2025

The French cybersecurity agency on Tuesday revealed that a number of entities spanning governmental, telecommunications, media, finance, and transport sectors in the country were impacted by a malicious campaign undertaken by a Chinese hacking group by weaponizing several zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices. The campaign, detected…

Continue Reading

China-linked Salt Typhoon Exploits Critical Cisco Vulnerability to Target Canadian Telecom

post, juni 24, 2025

The Canadian Centre for Cyber Security and the U.S. Federal Bureau of Investigation (FBI) have issued an advisory warning of cyber attacks mounted by the China-linked Salt Typhoon actors to breach major global telecommunications providers as part of a cyber espionage campaign. The attackers exploited a critical Cisco IOS XE software (CVE-2023-20198, CVSS score:…

Continue Reading

China Is Studying How to Hack and Crash Our Power Grids

post, juni 19, 2025juni 23, 2025

Over the past several weeks, I’ve been conducting a large-scale bibliometric study on publicly available Chinese academic literature related to hacking and crashing Western power grids. In this article, I’m sharing the main findings of that study. EDIT (20.6.2025, 8:54 CET): All of the Chinese academic articles I examined are…

Continue Reading

Over 70 Organizations Across Multiple Sectors Targeted by China-Linked Cyber Espionage Group

post, juni 9, 2025juni 10, 2025

The reconnaissance activity targeting American cybersecurity company SentinelOne was part of a broader set of partially-related intrusions into several targets between July 2024 and March 2025. “The victimology includes a South Asian government entity, a European media organization, and more than 70 organizations across a wide range of sectors,” SentinelOne…

Continue Reading

Tsjechië: China zit achter cyberaanval op ministerie van Buitenlandse Zaken

post, mei 28, 2025juli 3, 2025

Tsjechië houdt een Chinese groep hackers verantwoordelijk voor een cyberaanval op het ministerie van Buitenlandse Zaken. Volgens de Tsjechen gaat het om een “kwaadaardige cybercampagne”, gericht op een netwerk dat gebruikt werd voor niet-geheime communicatie. Het land stelt dat de aan China gelinkte groep APT31 daar vermoedelijk achter zit. Die…

Continue Reading
  • Previous
  • 1
  • 2
  • 3
  • …
  • 5
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes