Beijing's Backstage Pass: How China Hacked Congress While We Were All Looking at TikTok episode artwork

EPISODE · Jan 9, 2026 · 5 MIN

Beijing's Backstage Pass: How China Hacked Congress While We Were All Looking at TikTok

from Red Alert: China's Daily Cyber Moves · host Inception Point AI

This is your Red Alert: China's Daily Cyber Moves podcast. Name’s Ting, and listeners, we are on Red Alert. In the last 72 hours, China-linked operators have been moving quietly but fast across global networks, and the blast radius points straight at U.S. interests. Government Executive reports that Chinese hackers have targeted email systems for staff on key House committees, including Foreign Affairs, Intelligence, and Armed Services, likely tied to the notorious Salt Typhoon crew that already burrowed into major U.S. telecoms like AT&T and Verizon for years. Techdirt’s deep dive on Salt Typhoon shows they once had historic access to phone and email traffic for top U.S. officials, and the new congressional email hits look like Phase Two of that same campaign. Timeline it with me. First, late last year, Salt Typhoon’s telecom hack finally comes into focus: years of undetected access, then another year of persistence even after discovery, thanks to sloppy defaults and legal teams telling engineers to stop hunting for intrusions, as reported by Techdirt. That’s your groundwork: long-term wiretap on U.S. communications. Fast forward to this week. According to Government Executive and analysis at Breached Company, Chinese state-aligned actors are now inside House staff email systems, likely pivoting from the telecom insight they already harvested. SecurityWeek notes this fits a broader pattern: Chinese cyberattacks against U.S. government emails as part of a wider espionage push, while simultaneously ramping operations against Taiwan. At the same time, Cisco Talos and Cyware’s January 9 threat briefing flag UAT-7290, a China-linked group using Linux malware and Operational Relay Box nodes to compromise telecoms in South Asia and Southeastern Europe. Those ORB nodes can serve as global proxies and launch pads, meaning U.S. networks see traffic that looks “foreign and benign,” but is really Beijing’s Ministry of State Security bouncing signals off third countries. On the U.S. side, CISA just retired ten legacy Emergency Directives, as reported by BackBox and The Hacker News, folding their protections into broader guidance. That’s not an all-clear; that’s CISA saying, “You should already be doing this by default,” even as China-linked crews are exploiting SonicWall VPN appliances and VMware ESXi zero-days, according to BleepingComputer and The Hacker News, to gain hypervisor-level control in environments that often host U.S. government and defense contractors. So what are the live defensive actions? Patch SonicWall and ESXi yesterday; lock down Microsoft 365 and enforce MFA across all admin portals; audit mail routing so internal spoofing and domain misconfig don’t give Chinese phishers a free pass, as Microsoft’s own threat intel team recently warned. For congressional, state, and contractor networks, assume email and VoIP metadata may already be compromised and move to strict least-privilege, hardware-backed authentication, and continuous anom This content was created in partnership and with the help of Artificial Intelligence AI.

Episode metadata supplied by the publisher feed · Published Jan 9, 2026

Embed this episode

NOW PLAYING

Beijing's Backstage Pass: How China Hacked Congress While We Were All Looking at TikTok

0:00 5:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Red Alert: China's Daily Cyber Moves?

This episode is 5 minutes long.

When was this Red Alert: China's Daily Cyber Moves episode published?

This episode was published on January 9, 2026.

Can I download this Red Alert: China's Daily Cyber Moves episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!