The Cyber Resilience Brief: A SafeBreach Podcast

Ep. 58 - Double Dragon: How China's APT 41 Works for the State by Day — and Itself by Night

9 min · 13. maj 2026
Billede af episoden Ep. 58 - Double Dragon: How China's APT 41 Works for the State by Day — and Itself by Night

Description

China's cyber shadow has already reached your software. APT 41 — known as Double Dragon — isn't just stealing state secrets. They've pioneered a new generation of supply chain attacks, trojanizing the shared code libraries that thousands of organizations trust without question. And their latest splinter unit, UAT 7290, has been inside North American developer environments for over a year — not triggering anything, just watching, learning, and waiting to strike in a way that looks completely native. In this episode, Tova Dvorin and Adrian Culley expose the group that breaks every rule of traditional espionage: how the MSS built an elite hacker force by letting them run their own criminal enterprise on the side, how APT 41 turned the video gaming industry into a personal ATM worth millions, and why China's 2026 cybersecurity law has given these groups a 48-hour head start on every new exploit.

Comments

0

Be the first to comment

Sign up now and become a member of the The Cyber Resilience Brief: A SafeBreach Podcast community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

69 episodes

episode Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools artwork

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud" worm across npm and PyPI, npm account takeovers via expired recovery domains, and five concrete defenses — starting with searching your GitHub org for "tpcp-docs" right now. Read more on our blog: https://www.safebreach.com/blog/teampcp-supply-chain-attacks-fbi-flash-alert-20260702-01-safebreach-coverage/ [https://www.safebreach.com/blog/teampcp-supply-chain-attacks-fbi-flash-alert-20260702-01-safebreach-coverage/] #cybersecurity #infosec #CISO #supplychainsecurity #TeamPCP #CICD #BAS #SafeBreach

5. juli 202617 min
episode Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program artwork

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

On June 22, 2026, the heads of all six Five Eyes cyber agencies — GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB — signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn't the same as proven controls, and why legacy systems are now strategic liabilities for the board, not the IT team. A clear-eyed look at validation, assumed breach, and what CISOs should do Monday morning. Read the full Five Eyes statement on the CISA website: https://www.cisa.gov/news-events/news/five-eyes-cyber-security-agencies-statement [https://www.cisa.gov/news-events/news/five-eyes-cyber-security-agencies-statement] #cybersecurity #infosec #CISO #FiveEyes #CISA #NSA #GCHQ #adversarialexposurevalidation #cyberresilience #SafeBreach

1. juli 202618 min