EPISODE · Jun 8, 2026 · 3 MIN
Ting Spills Tea: China's Cyber Crews Are Living Rent-Free in US Power Grids and Nobody's Kicking Them Out Yet
from Red Alert: China's Daily Cyber Moves · host Inception Point AI
This is your Red Alert: China's Daily Cyber Moves podcast. I’m Ting, and Red Alert: China’s Daily Cyber Moves is lit up again, so let’s jack straight into what’s hitting US networks right now. Over the past few days, US cyber defenders have been watching a steady drumbeat of activity from China-linked groups like Volt Typhoon, APT31, and APT41 focusing on critical infrastructure in places like Texas, California, and the Eastern seaboard. Microsoft and Mandiant have been flagging how Volt Typhoon keeps burrowing into routers and firewalls from brands like Cisco and Fortinet, living off the land with legit admin tools to stay ghosted inside power, water, and port networks. Timeline-wise, it kicked up over the weekend: first wave, broad scanning of utilities and telecoms, hitting exposed VPNs and unpatched edge devices. Then, late night, a second wave: password-spray attacks on government and defense contractors’ Microsoft 365 and Okta accounts. By dawn, several mid-size municipal networks in the US had to isolate segments because of suspicious PowerShell and WMI activity that looked exactly like prior Chinese tradecraft called out by CISA and the FBI. CISA’s recent emergency-style advisories and joint alerts with the FBI and NSA have been crystal clear: China is not just going after data, they are positioning for potential disruption. The agencies keep warning about pre-positioned access inside sectors like energy, pipelines, and transportation, especially in locations tied to Pacific and Atlantic ports and to major data centers. New twist in the last few days: more focus on software supply chain footholds. Think smaller IT service providers in Virginia, Colorado, and Florida getting popped first, then quietly used to pivot into bigger healthcare and finance networks. CrowdStrike and Recorded Future analysts have been calling out an uptick in code-signing token theft and persistent abuse of cloud identities rather than noisy malware. Right now, active threats for US targets include stealthy lateral movement inside Windows domains, DNS tunneling for data exfiltration, and quiet manipulation of logging on security appliances so intrusions look like boring network noise. Cloud workloads on Azure and AWS with overly permissive roles are especially ripe targets. Defensive actions that CISA, NSA, and the FBI keep hammering: enforce phishing-resistant multifactor like FIDO keys on all admin and remote access accounts, rip and replace or at least patch and segment end-of-life routers and VPNs, adopt least privilege in both on-prem and cloud, and aggressively hunt for living-off-the-land behavior in PowerShell logs, WMI, and scheduled tasks, not just malware signatures. Potential escalation scenarios? If geopolitical tensions spike over Taiwan or the South China Sea, those quiet Chinese footholds inside US power grids, ports, and satellite links could shift from reconnaissance to disruption: timed outages, corrupted logistics data, or GPS spoofing affecting aviation and shipping. The nightmare scenario is simultaneous, coordinated disruptions across multiple states, forcing the US to choose between rapid public attribution and keeping some access quiet for intelligence reasons. I’m Ting, thanks for tuning in, stay patched, stay paranoid, and don’t forget to subscribe. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta
Embed this episode
Ready to play
Ting Spills Tea: China's Cyber Crews Are Living Rent-Free in US Power Grids and Nobody's Kicking Them Out Yet
No transcript for this episode yet
Similar Episodes
No similar episodes found.