Digital Dragon Watch: Weekly China Cyber Alert

China's Data Lockdown Gets Real While Scam Centers Level Up: Your Boring But Brilliant Defense Playbook

3 min · I går
episode China's Data Lockdown Gets Real While Scam Centers Level Up: Your Boring But Brilliant Defense Playbook cover

Description

This is your Digital Dragon Watch: Weekly China Cyber Alert podcast. Ting here, and the last seven days in China cyber have been less fireworks, more trench warfare. The most concrete official development came from China’s own data-security machinery: the Cyberspace Administration of China issued its new Measures for Network Data Security Risk Assessment, which tighten how important data handlers must assess risk, report findings, and coordinate with sector regulators and public-security authorities[5]. That matters because it formalizes a more procedural, audit-heavy defense posture in China, with annual assessments for important data handlers and stricter supervision of high-risk data processing[5]. On the threat side, the headline remains the same, but the tools keep evolving. The clearest new attack-vector signal in the available reporting is not a single dramatic breach, but the continued rise of scam-center and transnational fraud infrastructure. In the United States, Judge Jeanine Pirro said at Google DC that her Scam Center Strike Force is using public-private collaboration to dismantle transnational criminal organizations, freeze illicit funds, and shut down scam operations[2]. That is a strong sign that Washington sees the China-linked fraud ecosystem as a live and organized threat, not just isolated phishing spam[2]. For China-related cyber risk, the dangerous part is the blend of technical intrusion and financial deception. The pattern now includes fraud networks that can pivot across borders, use social engineering, and exploit weak identity verification in business workflows. Separately, the broader security conversation around China still centers on state-linked collection, commercial espionage, and data aggregation, which is why the compliance shift in Beijing is so important: it shows regulators are treating data flow itself as a security perimeter, not just the server room[5]. Targeted sectors over the past week remain the usual high-value set: government, telecom, finance, and companies handling important or sensitive data, with scam and fraud operations also putting ordinary users and businesses in the blast radius[2][5]. The strongest defensive advice from the official and expert messaging is boring in the best way: review emerging threats regularly, implement strong cybersecurity controls, and keep a close eye on scam tactics targeting businesses[2]. For organizations handling China-related data, the practical response is to map where important data moves, assign a named risk owner, document assessments, and be ready to prove authenticity to regulators[5]. For listeners trying to stay protected, the playbook is straightforward. Tighten identity checks, restrict privileged access, segment sensitive data, monitor for unusual transfers, and train staff to spot business-email compromise, fake executive requests, and payment diversion schemes. If your operation touches China-linked suppliers, customers, or data flows, assume the attack surface includes legal compliance, fraud, and technical intrusion all at once[2][5]. Thanks for tuning in, subscribe for more, and this has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta

Comments

0

Be the first to comment

Sign up now and become a member of the Digital Dragon Watch: Weekly China Cyber Alert community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

256 episodes

episode China's Data Lockdown Gets Real While Scam Centers Level Up: Your Boring But Brilliant Defense Playbook artwork

China's Data Lockdown Gets Real While Scam Centers Level Up: Your Boring But Brilliant Defense Playbook

This is your Digital Dragon Watch: Weekly China Cyber Alert podcast. Ting here, and the last seven days in China cyber have been less fireworks, more trench warfare. The most concrete official development came from China’s own data-security machinery: the Cyberspace Administration of China issued its new Measures for Network Data Security Risk Assessment, which tighten how important data handlers must assess risk, report findings, and coordinate with sector regulators and public-security authorities[5]. That matters because it formalizes a more procedural, audit-heavy defense posture in China, with annual assessments for important data handlers and stricter supervision of high-risk data processing[5]. On the threat side, the headline remains the same, but the tools keep evolving. The clearest new attack-vector signal in the available reporting is not a single dramatic breach, but the continued rise of scam-center and transnational fraud infrastructure. In the United States, Judge Jeanine Pirro said at Google DC that her Scam Center Strike Force is using public-private collaboration to dismantle transnational criminal organizations, freeze illicit funds, and shut down scam operations[2]. That is a strong sign that Washington sees the China-linked fraud ecosystem as a live and organized threat, not just isolated phishing spam[2]. For China-related cyber risk, the dangerous part is the blend of technical intrusion and financial deception. The pattern now includes fraud networks that can pivot across borders, use social engineering, and exploit weak identity verification in business workflows. Separately, the broader security conversation around China still centers on state-linked collection, commercial espionage, and data aggregation, which is why the compliance shift in Beijing is so important: it shows regulators are treating data flow itself as a security perimeter, not just the server room[5]. Targeted sectors over the past week remain the usual high-value set: government, telecom, finance, and companies handling important or sensitive data, with scam and fraud operations also putting ordinary users and businesses in the blast radius[2][5]. The strongest defensive advice from the official and expert messaging is boring in the best way: review emerging threats regularly, implement strong cybersecurity controls, and keep a close eye on scam tactics targeting businesses[2]. For organizations handling China-related data, the practical response is to map where important data moves, assign a named risk owner, document assessments, and be ready to prove authenticity to regulators[5]. For listeners trying to stay protected, the playbook is straightforward. Tighten identity checks, restrict privileged access, segment sensitive data, monitor for unusual transfers, and train staff to spot business-email compromise, fake executive requests, and payment diversion schemes. If your operation touches China-linked suppliers, customers, or data flows, assume the attack surface includes legal compliance, fraud, and technical intrusion all at once[2][5]. Thanks for tuning in, subscribe for more, and this has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta

Yesterday3 min
episode PeopleSoft's Forgotten Back Door: How Chinese Hackers Are Raiding HR Data While IT Sleeps artwork

PeopleSoft's Forgotten Back Door: How Chinese Hackers Are Raiding HR Data While IT Sleeps

This is your Digital Dragon Watch: Weekly China Cyber Alert podcast. Hey listeners, I’m Ting, your slightly overcaffeinated Digital Dragon watcher, and the China cyber scene this week has been…busy. Let’s start with the big one: according to the latest F5 Labs Weekly Threat Bulletin for June 17, researchers tracked a China‑nexus intrusion set abusing Oracle PeopleSoft’s Environment Management Hub, that PSEMHUB service most admins forget exists. Attackers used it as a beachhead, dropped custom JSP webshells, then fanned out across networks using SSH credential spraying with a script literally named “_fanout.sh” tied to hard‑coded IPs like 142.11.200.186 and the domain azurenetfiles dot net. F5’s analysis notes classic “living off the land” behavior: reading config files like psappsrv dot cfg, stealing credentials, and pivoting toward databases and HR records. Target sectors here are exactly where PeopleSoft lives: US universities, healthcare networks, and state and local government ERP stacks. That means payroll, student records, and sensitive HR data are all on the potential menu if you’re behind on Oracle patching. On the government side, this kind of activity lines up squarely with what CISA, the FBI, and NSA have been warning about in their joint advisories on PRC state‑sponsored actors targeting critical infrastructure and enterprise apps. Even when there isn’t a brand‑new press conference, those standing advisories are effectively the US government saying: “We told you they’d do this, and they still are.” Now defenses, because I don’t like leaving you in doom mode. F5 Labs recommends killing the exposure at the source: disable PeopleSoft EMHub if you don’t need it, or at minimum block external access to /PSEMHUB and /PSIGW/HttpListeningConnector at your perimeter firewalls, and hunt for unexpected JSP files under PSEMHUB dot war. They also call for default‑deny egress from PeopleSoft servers, blocking SMB and SSH outbound, and enforcing strong, unique passwords plus SSH key‑based admin access. That’s very much in line with what US government guidance from CISA’s Known Exploited Vulnerabilities catalog and their secure‑by‑design initiative has been preaching. Zooming out across the week, multiple industry reports and threat‑intel feeds continue to flag a rise in China‑linked operations against the US tech sector and cloud‑adjacent services, including long‑term data theft using clever abuse of legitimate features like email forwarding rules and cloud storage links rather than noisy malware. Those campaigns are hitting SaaS providers, semiconductor firms, and AI companies—anything holding valuable IP or training data. So what should you, my loyal cyber dragons, do? Expert recommendations are converging: aggressively patch any internet‑facing enterprise apps, especially Oracle, VPNs, and SSO; segment critical business systems from general user networks; enforce phishing‑resistant MFA; and feed your SIEM with detections for unusual admin activity, webshell patterns, and odd outbound traffic from business apps that “should never talk to the internet.” That’s your Digital Dragon Watch for this week. Thanks for tuning in, and don’t forget to subscribe so you never miss a signal in the noise. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta

17. juni 20263 min
episode Splunk Gets Pwned, Linux Goes Rogue, and China's Decade-Long SSH Backdoor Finally Exposed artwork

Splunk Gets Pwned, Linux Goes Rogue, and China's Decade-Long SSH Backdoor Finally Exposed

This is your Digital Dragon Watch: Weekly China Cyber Alert podcast. I’m Ting, your Digital Dragon Watch host, and listeners, we’ve had a very busy China‑cyber week. Let’s start with the loudest alarm: the Splunk Enterprise flaw, CVE‑2026‑20253. Defend Network reports this is a critical unauthenticated remote code execution bug with a 9.8 severity score, giving attackers a near‑frictionless way to run code on unpatched Splunk servers. That’s catnip for China‑linked espionage crews who love anything that sits in the middle of logs and telemetry. Splunk has already pushed patches, and U.S. federal environments that rely on Splunk for SIEM are scrambling to harden internet‑facing instances, segment management networks, and turn on strict access controls. Right behind that, Defend Network also flags that over 400 Arch Linux AUR packages were hijacked this week to deliver a Rust infostealer and an eBPF rootkit into developer build chains. That’s textbook supply‑chain tradecraft, very much in line with historic China‑nexus campaigns that compromise devs first, enterprises later. Targets are any shop that casually pulls AUR packages into CI pipelines—so think software vendors, security tools, and anyone building from bleeding‑edge Linux. The most worrying long‑game detail is Velvet Ant. According to Defend Network, this China‑linked threat group quietly burrowed into Linux PAM and OpenSSH components for almost a decade, keeping persistent admin‑level access. That’s not smash‑and‑grab ransomware; that’s strategic positioning for espionage across governments, telcos, and cloud providers. It also explains why U.S. defenders keep finding “ghost” SSH activity that never mapped cleanly to known malware. On the crime‑plus‑espionage frontier, Google has filed a lawsuit—highlighted in Google’s own public communications and amplified on Instagram—against a China‑based phishing‑as‑a‑service network. The service, known as the Greatness‑style platform in earlier reporting, is accused of weaponizing AI, including Google’s Gemini, to generate convincing smishing lures against U.S. users. That lines up with the broader U.S. government push, including FBI outreach, to clamp down on infrastructure that industrializes credential theft. So what should you actually do about all this? Experts at Defend Network and U.S. government cyber advisors converge on a few points: patch Splunk immediately; audit any systems that built AUR packages recently and assume credentials are burned; rotate all SSH keys; and deeply inspect PAM and OpenSSH binaries for tampering. For executive and political targets, move social and email accounts to hardware security keys and lock down recovery flows to prevent AI‑turbocharged phishing from escalating into full account takeover. I’m Ting, and that’s your Digital Dragon Watch for this week. Thanks for tuning in, and don’t forget to subscribe so you don’t miss the next alert. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta

15. juni 20263 min
episode Dragon Weave Steals Your Login While Scammers Get Raided and AI Models Go Dark artwork

Dragon Weave Steals Your Login While Scammers Get Raided and AI Models Go Dark

This is your Digital Dragon Watch: Weekly China Cyber Alert podcast. Hey listeners, Ting here with your Digital Dragon Watch, and this week the China cyber scene has been busy. Let’s start with the sneakiest move: Operation Dragon Weave. According to a campaign brief circulating from Mandiant researchers, this is a China‑aligned espionage op that’s been quietly riding on hijacked authentication flows to spy on otherwise isolated networks in government, research, technology, and financial organizations. Instead of smashing firewalls, they piggyback on legit identity providers, abusing OAuth‑style token exchanges to move laterally once a single identity is compromised. That means one stolen admin login turns into a skeleton key for email, code repos, and cloud workloads. The new attack vector here is all about identity infrastructure as the soft underbelly. Analysts say Dragon Weave actors stand up look‑alike login portals, then chain that with token replay and consent‑grant abuse to gain long‑lived access that looks like normal traffic. Defenders are spotting this only by correlating impossible travel patterns and anomalous token reuse, not by any obvious malware signature. While Dragon Weave stalks the high end, law enforcement is grinding down the cyber‑crime ecosystem that often overlaps with China‑based infrastructure. Thailand’s Cyber Crime Investigation Bureau reported raids at 29 locations tied to Chinese scam call centers and digital currency fraud, linked to over 4,000 scam cases across the region. In parallel, India’s Cyberabad Police detailed an international cyber network with links to China and Cambodia in a 77‑lakh‑rupee fraud case, stressing how mule accounts, crypto exchanges, and cross‑border hosting are fused into one pipeline. This is the gray zone where criminal tooling and state‑grade tradecraft can cross‑pollinate. On the policy front, listeners should pay close attention to Washington’s latest AI export controls. The Washington Examiner reports that the White House moved to restrict Anthropic’s Fable 5 and Mythos 5 models after concerns that a China‑linked group had accessed Mythos 5 and potentially probed its guardrails. Administration officials pushed for geofencing and tighter export compliance, and Anthropic responded by pulling the models from all users while they rework access controls. That is a clear signal that advanced AI models are now officially treated as dual‑use cyber capability when China is in the threat model. Meanwhile, the narrative fight continues. In the Philippines, Chinese diplomats publicly pushed back after Philippine Coast Guard officer Jay Tarriela raised alarms about data theft and cyber activity tied to facilities near Bajo de Masinloc. Beijing’s embassy accused Manila officials and media of “groundless” speculation about Chinese cyber attacks. Even when the packets are invisible, the information war is very visible. So what should you actually do this week? Identity is the new perimeter, so follow the Dragon Weave lessons: enforce phishing‑resistant multi‑factor authentication like FIDO2 keys on all admin and developer accounts; lock down OAuth consent so users cannot grant risky third‑party access without security review; and log every token issuance and refresh event so your SOC can hunt for replay and anomalous geography. If you’re running a US‑based tech or financial shop, align with recent US government guidance: map your exposure to Chinese cloud regions and vendors, review access to frontier AI models that could be targeted for jailbreak research, and treat vendor identities with the same scrutiny as your own. And because the scam infrastructure busted in Thailand and India shows how global this is, assume your users are being socially engineered through Chinese‑language and English‑language lures alike. Push security awareness that explains real campaign names like Dragon Weave, not just generic “don’t click stuff” slides. I’m Ting, thanking you for tuning in to Digital Dragon Watch: Weekly China Cyber Alert. Make sure you subscribe so you don’t miss next week’s intel drop. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta

14. juni 20264 min
episode Dragon's Shopping Spree: Beijing's 29-Minute Smash and Grab Hits AI Labs and Logistics Giants artwork

Dragon's Shopping Spree: Beijing's 29-Minute Smash and Grab Hits AI Labs and Logistics Giants

This is your Digital Dragon Watch: Weekly China Cyber Alert podcast. Hey listeners, Ting here with your Digital Dragon Watch, and the last week in China cyber has been…busy. Let’s start with the big strategic picture. CrowdStrike’s latest reporting says China‑nexus hacking groups ramped intrusion activity by 38 percent in 2025, with an 85 percent spike against logistics companies and major pressure on tech and telecom.[2][5] Adam Meyers at CrowdStrike even called logistics “probably the top target” for Chinese threat actors. That trend hasn’t slowed this week: shipping, cloud providers, and undersea‑cable–adjacent networks are still getting hammered as Beijing tries to map and potentially disrupt global supply chains. The favorite new‑ish attack vector? Edge devices. According to CrowdStrike, roughly 40 percent of China‑linked exploits last year hit internet‑facing VPNs, firewalls, and gateways, and 67 percent of those bugs gave immediate system access.[2] Over the past few days, several US and European incident‑response teams have quietly flagged fresh compromises in unpatched VPN appliances at mid‑size cloud and telecom providers, tracking back to familiar China‑nexus clusters like Warp Panda and Phantom Panda mentioned in the CrowdStrike report. While those edge hits are quietly exfiltrating data, another thrust is pure AI theft. CrowdStrike’s “China Stealing the AI Tech It Can’t Build” analysis describes how Chinese operators are using cyberespionage as industrial policy to close the AI innovation gap.[5] In the last week, multiple US AI startups have reported targeted phishing and OAuth abuse against their MLOps platforms, mirroring techniques in that report: credential‑stuffing against admin dashboards, followed by rapid grab‑and‑go of model weights and training data. Breakout time is now averaging 29 minutes from first foothold to lateral movement.[2] That’s not hacking; that’s smash‑and‑grab with a stopwatch. On the defensive side, US government response is getting sharper. The FBI, through ongoing campaigns like Operation Riptide highlighted by FBI field offices, keeps reminding companies that state‑sponsored and criminal activity are blurring, and is leaning hard on rapid reporting of China‑linked intrusions.[10] CISA has been pushing joint advisories urging immediate patching of edge devices within 72 hours of disclosure, tighter network segmentation, and continuous monitoring for anomalous traffic from VPNs and firewalls—exactly the weaknesses Chinese actors are exploiting, according to CrowdStrike’s data.[2] So what should you do this week, not someday? First, treat every VPN, firewall, and gateway like it’s already under attack: patch fast, enable strict access controls, and send those logs to something that actually gets looked at. Second, if you’re in logistics, telecom, or AI, assume you’re on a shopping list in Beijing; lock down code repositories, MLOps consoles, and any exposed admin panels. Third, follow CISA and FBI alerts in real time, and rehearse an incident‑response plan that assumes a China‑nexus actor moves in under half an hour. I’m Ting, keeping an eye on the digital dragon so you don’t have to. Thanks for tuning in, and don’t forget to subscribe. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta

10. juni 20263 min