EPISODE · Dec 26, 2025 · 3 MIN
China's Hacking Blitz: DNS Poison, Cisco Zero-Day Chaos, and Trump 2.0 Doomsday Moves
from Red Alert: China's Daily Cyber Moves · host Inception Point AI
This is your Red Alert: China's Daily Cyber Moves podcast. Hey listeners, Ting here, your go-to cyber sleuth on all things China hacking mayhem. Buckle up, because the past few days have been a red alert frenzy with Chinese APT crews dialing up the heat on US targets—think Salt Typhoon still burrowing into telecom giants like AT&T and Verizon, per US intelligence chatter. Today, December 26th, Kaspersky drops the bomb: China-linked Evasive Panda, aka Bronze Highland or Daggerfly, ran a slick DNS poisoning op from November 2022 to 2024, poisoning requests to sling their MgBot backdoor at high-value marks. But get this—they hit victims in Türkiye, China, and India, with adversary-in-the-middle tricks hijacking legit sites like dictionary.com to drop loaders and encrypted PNG shellcode. US ears perked up because Volexity caught them poisoning an unnamed ISP in August 2024 to push bad updates—classic escalation tactic that could easily pivot stateside. Flash back to December 18th: Cisco screams about a zero-day in their AsyncOS Email Security appliances, exploited by China-nexus UAT-9686 since at least December 10th. These creeps wormed into Secure Email Gateways and Web Managers, grabbing creds for espionage goldmines. CISA's Known Exploited Vulnerabilities catalog lit up too, flagging ASUS Live Update's CVE-2025-59374 supply chain mess—Chinese hackers love those embedded code bombs. Then December 17th, Check Point unmasks Ink Dragon, or Jewelbug, hammering European governments with ShadowPad and FINALDRAFT malware since July, but their Southeast Asia and South America hits scream global reach, eyeing US allies. Timeline's brutal: December 18th also sees LongNosedGoblin, a fresh China crew per ESET, using Windows Group Policy to plant espionage tools in Southeast Asia and Japan gov nets since September 2023. No direct US hits reported, but Salt Typhoon's telecom siege—ongoing per SIIT reports—has CISA and FBI issuing emergency alerts for multi-factor checks and network segmentation. Active threats? DNS poisoning, SSL VPN bypasses like Fortinet's CVE-2020-12812 (still popping December 25th), and phishing kits from China scam groups pushing fake e-com sites for card skims, Krebs on Security warns. Defensive playbook: Patch Cisco AsyncOS now, hunt for anomalous DNS traffic with tools like Wireshark, enable strict 2FA everywhere, and segment telecom edges—Salt Typhoon lives in those misconfigs. Escalation scenarios? If Trump 2.0 pivots like Krebs predicts, China could amp hybrid ops: sabotage US energy via edge devices, pair with Taiwan arms sale sanctions on Northrop Grumman and Boeing. Picture MgBot in US ISPs, blending with AI flaws for stealthy C2. Congress warns Russia's in on it too, but China's the daily dagger. Stay vigilant, listeners—run those YARA scans and thanks for tuning in. Subscribe for more cyber spice! This has been a Quiet Please production, for more check out quietplease.ai. For more http://www.quietplease.ai Get the best d This content was created in partnership and with the help of Artificial Intelligence AI.
Embed this episode
NOW PLAYING
China's Hacking Blitz: DNS Poison, Cisco Zero-Day Chaos, and Trump 2.0 Doomsday Moves
No transcript for this episode yet
Similar Episodes
No similar episodes found.