EPISODE · Jan 23, 2026 · 3 MIN
Chinas Cyber Spies Are Living Rent-Free in Your Firewall and Other Tech Horror Stories This title is 98 characters including spaces.
from Digital Dragon Watch: Weekly China Cyber Alert · host Inception Point AI
This is your Digital Dragon Watch: Weekly China Cyber Alert podcast. Hey listeners, Ting here with your Digital Dragon Watch weekly China cyber alert, and let me tell you, this week has been absolutely wild in the threat landscape. Let's jump straight into the chaos. Chinese intelligence services have compromised twenty thousand FortiGate systems worldwide, stealing configuration files that basically hand attackers the keys to the kingdom, passwords, VPN credentials, firewall rules, everything. The Dutch Military Intelligence Service revealed this exploitation started at least two months before Fortinet even disclosed the vulnerability back in December twenty twenty-two. But here's the terrifying part that keeps security experts up at night, the Chinese installed backdoors that survive firmware updates. You can wipe the device completely and the backdoor persists. Even with security patches installed, according to the Dutch MIVD, the state actors maintain continuous access. Google's Mandiant team documented another Chinese group called UNC5820 exploiting FortiManager starting in June twenty twenty-four to steal credentials from over fifty organizations. Fortinet didn't issue a public advisory until October, four months later. Security researcher Kevin Beaumont nailed it when he said he's not confident that Fortinet's narrative about protecting customers through delayed disclosure is actually protecting anyone. The bigger picture here involves China's Volt Typhoon campaign, which CISA confirmed uses Fortinet vulnerabilities as a primary entry method into US and UK critical infrastructure. We're talking about pre-positioning for potential destructive attacks, not just intelligence gathering. This is systematic infrastructure development measured in operational years. Meanwhile, a Cyber Intelligence Report documents that the PRC is conducting approximately two point six million cyberattacks daily. Many target energy sectors, hospitals, banks, and emergency services, coordinated with Chinese military exercises and political events. Recent campaigns include Ink Dragon hacking governments with ShadowPad malware, APT group UAT-9686 targeting Cisco email gateways, and Evasive Panda using DNS poisoning to install backdoors. The US government response remains hampered. The Trump administration has shifted toward a more chaotic approach according to threat analysts, with program cuts reducing federal cybersecurity coordination. This degradation of US cyber defenses, particularly in indicators and warnings capabilities, leaves American infrastructure vulnerable to catastrophic attacks reminiscent of the Colonial Pipeline incident. For protection, experts recommend aggressively patching internet-facing appliances, removing direct internet exposure of management interfaces, enforcing multifactor authentication across VPN and RDP access, and treating management platforms as tier-zero assets deserving maximum security attention. Thanks for tuning in to D This content was created in partnership and with the help of Artificial Intelligence AI.
Embed this episode
NOW PLAYING
Chinas Cyber Spies Are Living Rent-Free in Your Firewall and Other Tech Horror Stories This title is 98 characters including spaces.
No transcript for this episode yet
Similar Episodes
No similar episodes found.