Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously. So says the Royal United Services Institute (RUSI), which suggests that the EU needs to do better in helping members assess the risk and take appropriate action to safeguard the entire bloc. The UK-based think tank said in a report today that the EU should develop a new risk assessment framework that applies to all members and strengthens its own powers, without encroaching on members’ rights to set their own national security policies. It must delicately balance the need to secure the union, while maintaining the flexibility that both allows members to set domestic policies and lawmakers to account for different risk profiles across different sectors. The risks affecting telecoms will not necessarily apply to other sectors in the same way. Speaking of telecoms, currently there is only the voluntary EU Toolbox for 5G Security framework – voluntary being the operative word here, as only 10 of 27 members have fully implemented it since it launched in January 2020. On paper, it somewhat sets out to achieve what RUSI is calling for: a harmonized set of standards to mitigate 5G-related security risks affecting member states. Addressing the frustration over the lack of adoption, the European Commission proposed amendments to the Cyber Security Act (CSA) earlier this year that would allow it to build a list of untrusted vendors that members must preclude from the networks of 18 critical sectors. If passed, any countries using equipment from designated vendors would be forced to rip and replace it within 36 months. The EC has already indicated that it would suggest Huawei and ZTE be listed, should the amendments pass. But before the EU gets busy listing vendors it considers high-risk, it first needs to decide what a high-risk vendor even is. There is still no official definition, nor is it a legal category, and at present, it allows countries to wangle their way around these descriptions to buy the tech they want, bypassing whatever scrutiny may come their way should the CSA amendments come into force. RUSI’s researchers used Germany, Spain, and the UK as examples of how three countries can treat foreign tech vendors, such as Huawei and ZTE, very differently. Germany’s most important trading partner is China, a relationship worth €251.8 billion ($284.4 billion) annually, and historically the Bund has opted to preserve these valuable economic ties in favor of reducing supply chain risk. Under Chancellor Friedrich Merz, this is slowly changing, although RUSI does not expect to see a material shift in the makeup of Germany’s 5G RAN stack in the near future. Chinese suppliers accounted for an estimated 59 percent of the country’s 5G RAN in 2024. Chinese equipment accounted for an estimated 32 percent of Spain’s 5G RAN in 2024, although that share is expected to shrink. The debate intensified after last year’s controversy, when Spain awarded Huawei a contract involving the storage of judicial wiretap recordings. Spain’s past procurement decisions have shown it to often favor the most cost-effective option, and its government does not share the same national security concerns about China as the UK or US, or at least not to the same degree. The UK, meanwhile, looks set to completely eradicate Chinese technology from its telecoms network by the end of next year, and has bent to the US’ vehement demands that Huawei is bad, bad news for Western geopolitical security. Real security risks RUSI stated that concerns about Chinese IT vendors “are well-founded,” and that it is true that the Chinese government can empower authorities to exercise control over companies like Huawei. This includes providing the state with data on demand, hosting Chinese Communist Party (CCP) representatives, and reporting activity that signals a threat to national security. There is an additional law that requires tech companies to not just report vulnerabilities to the country’s government within 48 hours of discovery, but also to withhold the same disclosure from China’s overseas counterparts, except for the product vendor. “This converts China’s private sector security research into a state-controlled pipeline that grants intelligence services privileged early access to exploitable vulnerabilities,” RUSI said. Factoring in all of this, the country has also demonstrated the willingness and capability to launch cyberattacks against the critical national infrastructure of political adversaries, according to RUSI. Technical security aside, China’s technological advancements introduce economic risks, too. In some cases, its vendors have developed more capable products than equivalents in the EU or US, and sold them at more attractive prices. This advantage makes it difficult for some countries to justify the extra expense on non-Chinese equipment. In building a global reliance on its products, China could then introduce “unwelcome dependencies,” or cement itself as a dominant player in crucial supply chains, RUSI noted. China has shown in recent years that it is willing to exercise this influence, such as when it threatened Germany with “consequences” for the two countries’ economic ties during the heated 5G debate of 2019. Would a high-risk designation system work? One of the reasons why the think tank is calling for a more considered risk assessment framework for the EU is that there is no guarantee that what the EC is currently proposing in its CSA amendments will have much of an effect. Issuing blanket bans on companies, or countries, does not explicitly address the underlying security issues that make products vulnerable to attack. In other words, even if China were excluded entirely from the EU members’ tech stacks, the other vendors from ‘trusted’ countries have proved that they are unable to deliver penetration-proof software, which would open the door to attacks regardless. Remember, Salt Typhoon’s high-profile attack on US telco networks took place as recently as 2024. It should also be said that CSA-esque designations could apply to US companies, as some countries in Europe see US vendors as similarly risky, albeit for different reasons. Merz’s Germany is concerned about the relationship between the US and EU, for example, and similar concerns about dependence on Chinese technology could easily be applied to vendors in the US, should relations sour. In Spain, US cloud companies dominate, but anti-US sentiment is stronger than many realize, particularly around surveillance concerns. Those, along with higher prices from some non-Chinese suppliers, have reduced Spain’s appetite for ripping out equipment others deem high-risk. “One participant even noted that some officials view US legal instruments such as the Patriot Act as creating equivalent sovereignty risks to China’s National Intelligence Law, a narrative that is flawed when exploring the legislation, but politically convenient,” RUSI stated. The think tank suggested that if it wishes to enact change through policy, the EU must gather “greater economic courage” and a willingness to approach tech procurement as a means to secure its critical infrastructure, rather than “a compliance exercise.” ®
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid.
The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site.
Investigators identified him as KillSec's suspected
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years.
That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can
A suspected Chinese espionage group impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in phishing campaigns targeting AI policy experts at US universities, think tanks, and law firms, security researchers say. The bulk of these campaigns occurred in July, according to Proofpoint, which discovered the espionage attempts and attributed them to a China-aligned group it tracks as TA419. Proofpoint’s security alert comes a day after OpenAI accused China’s Moonshot AI of stealing the American models’ reasoning and other data in distillation attacks that began on July 1. “In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US,” Proofpoint threat-intelligence analyst Mark Kelly said in a Thursday report. Beginning July 8, TA419 sent phishing emails spoofing Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a prominent economist and foreign policy expert, to even more American AI policy experts at think tanks, universities, and law firms. The suspected spies’ emails invited their targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains. If the American AI expert replied, the Beijing-linked crew responded with a shortened URL promising to share additional details, but in reality pointing to an attacker-controlled domain. This page conducts a Cloudflare Turnstile check behind a phony OneDrive loading screen, and then redirects the victim to an attacker-in-the-middle (AitM) credential phishing page that steals the victim’s cloud account login information. The July 2026 campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain. In February - as US military officials pressured Anthropic to remove Claude’s safeguards - the Chinese spies spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank. This email used the subject line: “Request for Feedback on Military Integration of Claude.” TA419’s phishing chain targets Microsoft 365/Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). It’s built on open source Frameless BitB, which contains a Browser-in-the-Browser (BitB) overlay, an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365, and server-side substitution rules that inject the kit into proxied pages. TA419 typically uses Cloudflare’s content delivery network to hide the backend hosting IP address for its domains, and its credential phishing domains are usually themed around file sharing sites and cloud services - such as msfile[.]online and onecloudfilesync[.]com. It also impersonates specific organizations, including the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and Japanese Minister of Defense Shinjirō Koizumi’s official website (shinjirou[.]info). In total, the crew uses dozens of phishing and spoofed-sender domains, and phony email addresses. Proofpoint includes all of the ones it discovered in 2026, plus the timeline of when they were registered or first seen, so check out those indicators, too. TA419 and other Beijing-aligned crews will likely continue targeting AI and other policy experts working on technologies of interest to the Chinese government, according to the threat hunters. “Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys,” they recommend.®
A blue-team writeup on detecting a compromised MikroTik from its own config. Seven techniques, each with the collection command, the artifact it leaves behind, and a triage step. Feedback welcome.
Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers. No stolen password or unfortunate employee clicking a dodgy link is required. An attacker can send a specially crafted email to a vulnerable internet-facing server and potentially run commands, though Redmond notes the flaw affects only servers running Zimbra's optional SNMP monitoring package with notifications enabled. Zimbra fixed the flaw in version 10.1.20 on July 20, but CVE-2026-73570 wasn't publicly disclosed until August 13. Between July 28 and August 7, Redmond spotted two different scanning tools probing the same part of Zimbra later used in attacks. At first, the activity appears to have focused on finding vulnerable servers and testing the flaw. The attackers used a collection of common network utilities to make vulnerable systems call back to infrastructure they controlled, confirming they could execute commands. Once they found servers that played ball, things got messier. Microsoft's investigation found attackers deploying web shells and reverse shells, escalating their privileges, installing tools for persistent remote access, and running malicious code directly in memory. Some even tidied up after themselves. Microsoft said attackers temporarily changed permissions on public directories to plant web shells, then restored the original settings afterward in an apparent attempt to make their meddling harder to spot. The intruders also explored the wider Zimbra environments they landed in, identifying other mail servers and looking for trusted connections they could use to move between them. In some cases, existing SSH relationships between Zimbra systems gave them a route to neighboring servers. On at least one compromised machine, attackers turned their initial foothold into root access. They then set things up to keep running commands with the highest privileges without needing a password. Mailboxes were, unsurprisingly, also on the shopping list. Microsoft said attackers hunted for Zimbra credentials and authentication secrets that could potentially be used to access user accounts. One malicious tool it uncovered was built specifically to extract service account credentials and pull mailbox information from Zimbra's databases. In another incident, attackers bundled recent mailbox backups into an archive and tried to ship the haul to Azure Blob Storage using Microsoft's own AzCopy utility. Microsoft said it couldn't confirm from the evidence available whether the transfer actually succeeded. The company saw affected organizations across multiple regions and industries, with the attacks ranging from automated exploitation to more deliberate hands-on-keyboard activity. It hasn't attributed the activity to a particular crew. Admins running versions earlier than Zimbra 10.1.20 should update to 10.1.20 or later, while those unable to patch can reduce their exposure by removing the optional SNMP package or disabling SNMP notifications. Attackers, meanwhile, appear to have gotten there early, with Microsoft spotting probes for the flaw more than two weeks before it was publicly disclosed. ®
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again.
The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's
MI5 has warned that more than 100 UK-linked academics contributed to research projects allegedly funded to improve China's spying capabilities. The Security Service issued an unusually public espionage alert this week naming the China General Technology Research Institute (CGTRI), also translated as the China Academy of General Technology (CAGT). MI5 says the organization has "very strong ties" to China's Ministry of State Security (MSS), the country's civilian intelligence agency. According to MI5, CGTRI's "primary purpose" is to fund academic research that directly improves the MSS's technical espionage capabilities. More than 100 UK-linked academics have contributed to CGTRI-funded projects involving AI, cybersecurity, covert communications, and steganography, the agency said. Some may not have known who was ultimately financing the work. "This activity supports MSS espionage, which poses a threat to UK national security," MI5 said. MI5 isn't accusing all of the academics involved of knowingly helping Chinese intelligence. Its alert acknowledges that many institutions and individuals likely dealt with CGTRI "in good faith" because of what it describes as the organization's "obfuscated links" to the MSS. MI5 "strongly advised" UK universities to review immediately any current or planned collaboration with CGTRI and ensure that the MSS derives no further benefit from British research. Academics working with Chinese institutions are also being told to establish who is ultimately funding the research and make sure CGTRI isn't involved. Researchers may also want to brush up on the National Security Act 2023. MI5 specifically highlighted two offenses: assisting a foreign intelligence service under section 3 and obtaining a material benefit from one under section 17. Under section 3, a person can commit an offense if their conduct is likely to materially assist a foreign intelligence service with UK-related activities and they know, or "ought reasonably to know," that it is likely to do so. Section 17 separately covers accepting or retaining a material benefit when the recipient knows, or ought reasonably to know, that it came from a foreign intelligence service. Legitimate payment for lawful goods or services is excluded. Having publicly identified CGTRI's alleged links to Chinese intelligence, MI5 warned that any institution or researcher continuing to conduct work funded by the organization should seek independent legal advice. In other words, MI5 has put universities on notice: not knowing who was really behind the research money may have been understandable yesterday, but it is a considerably trickier argument today. ®
Welcome back to PWNED, the weekly column where we warn you about weak security practices. This week’s terrifying tale involves a lack of important patching and a humorously bad password belonging to the person in charge of tech security at a law firm. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story comes courtesy of Joe Brinkley, who is director of offensive security research and community at Cobalt, is known as “The Blind Hacker,” and has more than two decades of experience in information security. Joe was called in several years ago by a large, national law firm that wanted him to penetration test a smaller business they were about to acquire. What he discovered was a huge security hole and an even bigger embarrassment. Brinkley had audited the same law firm the previous year. At that time, he noted a number of holes and the attorneys had dutifully spent time and money on security software from the likes of Reliaquest and Dell to remediate what he found. “I shredded them. They were not in a very good security posture,” Brinkley told us. “They spent probably a half a million dollars to get patching and get through these things because they were trying to go through a merger and acquisition.” Unfortunately, even with their investment, the company failed to patch its Windows machines against BlueKeep, a major remote code execution vuln that was discovered, patched, and exploited in 2019. BlueKeep affects many versions of Windows, including Windows 2000, Windows Server 2008 R2, and Windows 7. Related vulns called DejaBlue also affected Windows 10. BlueKeep and its related security risks involve a flaw in Windows’ Remote Desktop Protocol that allows attackers to gain entry and execute remote code via port 3389. The vuln is wormable so an attacker could make it spread from one system to another. However, none of this filtered through to become a priority for the law firm. During his pentest, Brinkley used the BlueKeep vuln to get access to the org’s systems, where he found that the passwords were stored in plain text and easy to dump into a file, no decryption necessary. The usernames on the system were cleverly designed for security by obscurity. Instead of using the user’s real name or something like “admin,” they had names like “Yellow Banana” and “Red Apple” so attackers could not guess which one had the most privileges. Brinkley had no idea who Yellow Banana was, but he found that person’s password and it was perhaps the tackiest idea of a login we’ve ever heard. The password was “r3@lg00dp@$$w0rd,” which is “realgoodpassword” with some symbols and numbers substituted for letters. Not knowing who made the security faux pas, he took the password and included a screen shot of it in a presentation he delivered on system vulnerabilities that he gave to the law firm’s execs. While he was explaining that he had managed to penetrate 2,500 of the org’s computers, the CISO suddenly dropped an f-bomb. “Why the f*** is my password on the screen?” he complained, giving away the fact that he was Yellow Banana and thought that r3@lg00dp@$$w0rd was a good idea. So what can we learn from this tale of legal embarrassment? Always patch your Windows systems as soon as new patches become available and never use a cutesy password. Enabling 2FA and encrypting the passwords would probably have helped too. ®