This is your Red Alert: China's Daily Cyber Moves podcast.
Name’s Ting, your friendly neighborhood China-and-cyber nerd, and I’m going to walk you through the last few days of Red Alert: China’s daily cyber moves against the United States.
Let’s rewind to late weekend. Analysts at Fortinet’s FortiGuard Labs have been tracking a China‑linked espionage crew they call Salt Typhoon, also known in other reports as FamousSparrow, GhostEmperor, Earth Estries, and UNC2286. FortiGuard says this group has been quietly inside US telecoms and hospitality networks since at least 2019, hunting law‑enforcement data and government-adjacent traffic, and they are still active right now, leaning on tools like Cobalt Strike, ShadowPad, and SparrowDoor, plus fresh exploits for flaws like CVE‑2024‑3400 in Palo Alto PAN‑OS.
Over the past 72 hours, several threat intel feeds have flagged a spike in scanning and exploit attempts against perimeter devices used by US critical infrastructure operators, especially regional ISPs and data centers that feed government contractors and energy firms. Think of it as Beijing’s advanced persistent tourists shaking every digital doorknob on the backbone.
Around the same window, Dark Reading reported a Chinese campaign in Europe using a dual‑layer spear‑phishing technique and malware dubbed Azureveil against Czech and Taiwan‑linked organizations. The pattern matters for US listeners: first wave phishing to low‑value accounts, second wave to admins, with cloud‑focused payloads that blend into Microsoft 365 traffic. Swap the target list, and it’s a ready‑made playbook for US agencies and defense primes.
On the US policy side, Broadband Breakfast reports that President Donald Trump just signed a downsized AI cybersecurity executive order. It pushes NSA, CISA, and Treasury to build a classified system to vet powerful AI models and expand AI‑powered cyber tools across civilian agencies, but it keeps everything voluntary. That means while China is operationalizing AI for reconnaissance and phishing, US defenses are still in “coordination and clearinghouse” mode.
So what are CISA and the FBI doing? In the last few days their joint alerts, advisories, and Known Exploited Vulnerabilities list have been hammering the same themes: patch edge devices fast, segment OT from IT in energy and water, monitor for living‑off‑the‑land tools like PowerShell, WMI, and PsExec, and hunt for long‑dwell web shells and unusual lateral movement inside VPN and RDP logs. Behind closed doors, InfraGard and sector ISACs are treating Chinese activity against telecoms as a staging ground for potential disruptions if geopolitical tensions escalate.
Timeline it like this: weekend into Monday, surge in Chinese scanning and exploitation of network edge and cloud identity; Monday night into Tuesday, expanded intelligence linking that activity to known China-nexus sets like Salt Typhoon; Tuesday, the AI executive order lands, implicitly acknowledging that foreign adversaries—yes, that’s mostly China and Russia—are already using AI to amplify cyber operations.
Where could this escalate? Short term, listeners should expect more credential theft in managed service providers, more tampering with software update pipelines, and more quiet positioning inside communications networks that support US military logistics. In a Taiwan or South China Sea flashpoint, that positioning morphs from espionage to disruption: slowdowns in 911 call routing, selective outages around bases, or targeted hits on transportation management systems.
Defensive actions, right now: patch internet‑facing devices aggressively, enable phishing‑resistant MFA, baseline admin behavior, lock down service accounts, and rehearse incident response as if a Chinese threat actor is already in the network—because for some organizations, they are.
Thanks for tuning in, listeners. Don’t forget to subscribe so you don’t miss the next threat briefing. This has been a quiet please production, for more check out quiet please dot ai.
For more http://www.quietplease.ai
Get the best deals https://amzn.to/3ODvOta