Geek-Guy.com

Category: Asia Pacific

Treasury slaps sanctions on people, companies tied to North Korean IT worker schemes

The Treasury Department on Tuesday announced it has sanctioned a North Korean man participating in the widespread IT worker scheme, as well as others in a Russia-based IT worker operation that allegedly benefits the government of North Korea. It’s the second time in as many weeks that feds have taken action against people it says…

Italian police arrested a Chinese national suspected of cyberespionage on a U.S. warrant

Italian police arrested a Chinese national linked to Silk Typhoon APT group at Milan’s Malpensa Airport on a U.S. warrant. Italian police arrested a Chinese national, Zewei Xu (33), at Milan’s Malpensa Airport on a U.S. warrant. Xu was arrested at Malpensa Airport on July 3rd after arriving on a flight from China. Authorities accused…

GOP domestic policy bill includes hundreds of millions for military cyber

The tax and spending bill Congress sent to President Donald Trump and that he signed into law over the holiday weekend contains hundreds of millions of dollars for cybersecurity, with a heavy emphasis on military-related spending. The biggest single pot of money under the “One Big Beautiful Bill” would be for Cyber Command, a $250…

China’s AI unity fractures as Huawei faces model theft allegations from the Alibaba camp

Huawei’s AI research division has rejected claims that its Pangu Pro large language model copied elements from an Alibaba model, marking a significant escalation in China’s AI ecosystem as tech giants abandon their collaborative approach in favor of bitter public disputes. The telecommunications giant’s Noah Ark Lab issued a denial Saturday, after an entity called…

Taiwan flags security risks in popular Chinese apps after official probe

Taiwan warns Chinese apps like TikTok and WeChat pose security risks due to excessive data collection and data transfers to China. Taiwan National Security Bureau (NSB) warns that Chinese apps like TikTok, WeChat, Weibo, and Baidu Cloud pose security risks due to excessive data collection and data transfer to China, following an official inspection with…

Taiwan NSB Alerts Public on Data Risks from TikTok, Weibo, and RedNote Over China Ties

Taiwan’s National Security Bureau (NSB) has warned that China-developed applications like RedNote (aka Xiaohongshu), Weibo, TikTok, WeChat, and Baidu Cloud pose security risks due to excessive data collection and data transfer to China. The alert comes following an inspection of these apps carried out in coordination with the Ministry of Justice Investigation Bureau (MJIB) and…

NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors

Cybersecurity researchers have shed light on a previously undocumented threat actor called NightEagle (aka APT-Q-95) that has been observed targeting Microsoft Exchange servers as a part of a zero-day exploit chain designed to target government, defense, and technology sectors in China. According to QiAnXin’s RedDrip Team, the threat actor has been active since 2023 and…

Hunters International shuts ransomware operations, reportedly becomes an extortion-only gang called World Leaks

Ransomware gang Hunters International says it’s shutting down its operations for unexplained reasons, and is offering decryption keys to victim organizations. The offer of decryption keys could be good news for CISOs whose data were recently scrambled and who can’t find a way to decrypt the files. However, judging from the history of ransomware gangs…

Big Tech’s Mixed Response to U.S. Treasury Sanctions

In May 2025, the U.S. government sanctioned a Chinese national for operating a cloud provider linked to the majority of virtual currency investment scam websites reported to the FBI. But a new report finds the accused continues to operate a slew of established accounts at American tech companies — including Facebook, Github, PayPal and Twitter/X.…

US lets China buy semiconductor design software again

The US has lifted export restrictions on semiconductor design software to China, reversing a controversial policy imposed just six weeks ago that had threatened to cripple China’s chip design capabilities.  The three leading semiconductor design software providers, Synopsys, Cadence Design Systems, and Germany’s Siemens, announced they had been notified that export license requirements for business…

State Department Wants to Know Student Visa Applicants’ Myspace Accounts

New State Department guidance released this month instructs student visa applicants to “adjust the privacy settings on all of their social media profiles to ‘public,’” a task which will be difficult to accomplish as several social media services listed in the online visa application form haven’t been operational in years. The student visa form requires…

Chinesische Hacker haben über 1.000 SOHO-Geräte infiziert

Dutzende Cybercrime-Kampagnen mit Fokus auf Asien und die USA wurden als angebliche LAPD-Aktionen getarnt. FOTOGRIN – shutterstock.com Cybersecurity-Experten haben ein Netzwerk von mehr als 1.000 kompromittierten Small-Office- und Home-Office-Geräten (SOHO) entdeckt. Die Devices wurden laut den Experten dazu genutzt, eine langwierige Cyberspionage-Infrastrukturkampagne für chinesische Hacker-Gruppen zu ermöglichen. ShortLeash als zentrale Schadsoftware Das Strike-Team von SecurityScorecard…

GDPR violations prompt Germany to push Google and Apple to ban DeepSeek AI

Germany asked Google and Apple to remove DeepSeek AI from their app stores, citing GDPR violations over unlawful data collection and transfers to China. The Berlin Commissioner for Data Protection requested Google and Apple to remove the DeepSeek AI app from their app stores due to GDPR violations. On May 6, 2025, Berlin’s Data Protection Commissioner…

OpenAI: Latest news and insights

OpenAI is an artificial intelligence organization comprised of the non-profit OpenAI, Inc. and several for-profit subsidiaries. The company is perhaps best known for its ChatGPT chatbot, which launched in 2022, kicking off a period of massive disruption in the tech industry and beyond. A complicated and increasingly contentious relationship with Microsoft, ongoing legal issues over…

Security Affairs newsletter Round 530 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. The FBI warns that Scattered Spider is now targeting the airline sector LapDogs: China-nexus hackers Hijack…

Security Affairs newsletter Round 530 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. The FBI warns that Scattered Spider is now targeting the airline sector LapDogs: China-nexus hackers Hijack…

Security Affairs newsletter Round 530 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. The FBI warns that Scattered Spider is now targeting the airline sector LapDogs: China-nexus hackers Hijack…

LapDogs: China-nexus hackers Hijack 1,000+ SOHO devices for espionage

Over 1,000 SOHO devices were hacked in a China-linked spying campaign called LapDogs, forming a covert network to support cyber espionage. Security researchers at SecurityScorecard’s STRIKE team have uncovered a cyber espionage campaign, dubbed LapDogs, involving over 1,000 hacked SOHO (small office/home office) devices. These compromised devices formed a hidden network, called an Operational Relay…

LapDogs: China-nexus hackers Hijack 1,000+ SOHO devices for espionage

Over 1,000 SOHO devices were hacked in a China-linked spying campaign called LapDogs, forming a covert network to support cyber espionage. Security researchers at SecurityScorecard’s STRIKE team have uncovered a cyber espionage campaign, dubbed LapDogs, involving over 1,000 hacked SOHO (small office/home office) devices. These compromised devices formed a hidden network, called an Operational Relay…

LapDogs: China-nexus hackers Hijack 1,000+ SOHO devices for espionage

Over 1,000 SOHO devices were hacked in a China-linked spying campaign called LapDogs, forming a covert network to support cyber espionage. Security researchers at SecurityScorecard’s STRIKE team have uncovered a cyber espionage campaign, dubbed LapDogs, involving over 1,000 hacked SOHO (small office/home office) devices. These compromised devices formed a hidden network, called an Operational Relay…

Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign

Threat hunters have discovered a network of more than 1,000 compromised small office and home office (SOHO) devices that have been used to facilitate a prolonged cyber espionage infrastructure campaign for China-nexus hacking groups. The Operational Relay Box (ORB) network has been codenamed LapDogs by SecurityScorecard’s STRIKE team. “The LapDogs network has a high concentration…

PUBLOAD and Pubshell Malware Used in Mustang Panda’s Tibet-Specific Attack

A China-linked threat actor known as Mustang Panda has been attributed to a new cyber espionage campaign directed against the Tibetan community. The spear-phishing attacks leveraged topics related to Tibet, such as the 9th World Parliamentarians’ Convention on Tibet (WPCT), China’s education policy in the Tibet Autonomous Region (TAR), and a recently published book by…

OneClik APT campaign targets energy sector with stealthy backdoors

A OneClik campaign, likely carried out by China-linked actor, targets energy sectors using stealthy ClickOnce and Golang backdoors. Trellix cybersecurity researchers uncovered a new APT malware campaign, OneClik, targeting the energy, oil, and gas sectors. It abuses Microsoft’s ClickOnce deployment tech and custom Golang backdoors. While links to China-affiliated actors are suspected, attribution remains cautious.…

Stealth China-linked ORB network gaining footholds in US, East Asia

A recently discovered operational relay box (ORB) network controlled by a China-linked threat group already exceeds 1,000 devices and is growing across the United States and East Asia, SecurityScorecard said in a threat report released Monday.  The ORB network, which SecurityScorecard dubbed “LapDogs,” is primarily composed of routers designed for small or home offices but…

Microsoft startet neues europäisches Sicherheitsprogramm

Microsoft will die Cybersicherheit in Europa stärken. MeshCube – shutterstock.com Microsoft warnt davor, dass sich Ransomware-Gruppen und staatlich geförderte Akteure aus Russland, China, dem Iran und Nordkorea in Umfang und Raffinesse stetig weiterentwickeln. Europa dürfe daher nicht zögern, seine Verteidigungsmechanismen zu stärken. Der Tech-Konzern will deshalb mit einer neuen Initiative bestehende Schutzprogramme erweitern und gezielt…

Colossal breach exposes 4B Chinese user records in surveillance-grade database

A colossal data breach has reportedly exposed approximately four billion records containing personal information of hundreds of millions of users, primarily from China. The 631-gigabyte database was discovered sitting wide open on the internet, lacking even the most basic password protection, >according to cybersecurity firm Cybernews, which reported its findings based on its own research. What makes this…

Sean Cairncross has policy coordination in mind if confirmed as national cyber director

Sean Cairncross laid out his vision to senators Thursday for the Office of the National Cyber Director if he is confirmed to lead it. “A goal of mine is to make sure this office sits at the place that this committee and I believe Congress intended in the statute, and that is to lead cyber…

Top US cyber officials face divergent paths after Senate confirmation

Since the start of the Trump administration, the US federal government’s two top cybersecurity leadership positions have been vacant, but those roles are finally on the path to being filled. The first job is the director of the Cybersecurity and Infrastructure Security Agency (CISA), which has been vacant since former director Jen Easterly left on…

Rep. Garbarino: Ending CISA mobile app security program for feds sends ‘wrong signal’

The chairman of the House Homeland Security subcommittee on cybersecurity is apprehensive about the Department of Homeland Security’s plans to end a program that vets mobile apps for federal agencies. Rep. Andrew Garbarino, R-N.Y., sent a letter to DHS Secretary Kristi Noem on Thursday saying that especially in light of the massive Salt Typhoon telecommunications…

Top FBI cyber official Cynthia Kaiser exits for Halcyon

Cynthia Kaiser, a former top FBI cyber official, is joining the cybersecurity firm Halcyon this week as senior vice president of its newly created ransomware research center. Kaiser left the FBI last week after 20 years, serving most recently as deputy assistant director leading the bureau’s cyber policy, intelligence and engagement branch and eight years…

Top FBI cyber official Cynthia Kaiser exits for Halcyon

Cynthia Kaiser, a former top FBI cyber official, is joining the cybersecurity firm Halcyon this week as senior vice president of its newly created ransomware research center. Kaiser left the FBI last week after 20 years, serving most recently as deputy assistant director leading the bureau’s cyber policy, intelligence and engagement branch and eight years…

Top FBI cyber official Cynthia Kaiser exits for Halcyon

Cynthia Kaiser, a former top FBI cyber official, is joining the cybersecurity firm Halcyon this week as senior vice president of its newly created ransomware research center. Kaiser left the FBI last week after 20 years, serving most recently as deputy assistant director leading the bureau’s cyber policy, intelligence and engagement branch and eight years…

OpenAI’s Pitch to Trump: Rank the World on U.S. Tech Interests

OpenAI has always said it’s a different kind of Big Tech titan, founded not just to rack up a stratospheric valuation of $400 billion (and counting), but also to “ensure that artificial general intelligence benefits all of humanity.”  The meteoric machine-learning firm announced itself to the world in a December 2015 press release that lays…

OpenAI’s Pitch to Trump: Rank the World on U.S. Tech Interests

OpenAI has always said it’s a different kind of Big Tech titan, founded not just to rack up a stratospheric valuation of $400 billion (and counting), but also to “ensure that artificial general intelligence benefits all of humanity.”  The meteoric machine-learning firm announced itself to the world in a December 2015 press release that lays…

OpenAI’s Pitch to Trump: Rank the World on U.S. Tech Interests

OpenAI has always said it’s a different kind of Big Tech titan, founded not just to rack up a stratospheric valuation of $400 billion (and counting), but also to “ensure that artificial general intelligence benefits all of humanity.”  The meteoric machine-learning firm announced itself to the world in a December 2015 press release that lays…

China-Linked Hackers Exploit SAP and SQL Server Flaws in Attacks Across Asia and Brazil

The China-linked threat actor behind the recent in-the-wild exploitation of a critical security flaw in SAP NetWeaver has been attributed to a broader set of attacks targeting organizations in Brazil, India, and Southeast Asia since 2023. “The threat actor mainly targets the SQL injection vulnerabilities discovered on web applications to access the SQL servers of…

Meta Disrupts Influence Ops Targeting Romania, Azerbaijan, and Taiwan with Fake Personas

Meta on Thursday revealed that it disrupted three covert influence operations originating from Iran, China, and Romania during the first quarter of 2025. “We detected and removed these campaigns before they were able to build authentic audiences on our apps,” the social media giant said in its quarterly Adversarial Threat Report. This included a network…

Tensions flare between the US and China over Huawei’s AI chips

Just a few weeks after the U.S. and China made significant steps to de-escalate the growing trade war between the two countries, tensions are flaring again — this time over semiconductors. China’s Commerce Ministry in Beijing released a statement on Wednesday that threatened legal action against anyone who enforces U.S. export restrictions on Huawei’s AI chips,…

Critical flaw in OpenPGP.js raises alarms for encrypted email services

A newly discovered flaw in OpenPGP.js, a JavaScript cryptography library used by services like Proton Mail, could allow attackers to spoof messages that appear securely signed and encrypted, security researchers said. The flaw, identified as CVE-2025-47934 and assigned a critical severity rating, was discovered by Edoardo Geraci and Thomas Rinsma of Codean Labs. It stems…

‘Whatever we did was not enough’: How Salt Typhoon slipped through the government’s blind spots

The first time some of the largest telecom companies in the world heard of Salt Typhoon was in a Wall Street Journal article. The story, which was published last September, blindsided company executives and industry insiders. As news of the attack on the country’s broadband networks broke, the scope and severity of the breach became…

Chinese Hackers Deploy MarsSnake Backdoor in Multi-Year Attack on Saudi Organization

Threat hunters have exposed the tactics of a China-aligned threat actor called UnsolicitedBooker that targeted an unnamed international organization in Saudi Arabia with a previously undocumented backdoor dubbed MarsSnake. ESET, which first discovered the hacking group’s intrusions targeting the entity in March 2023 and again a year later, said the activity leverages spear-phishing emails using

U.S. lawmakers have concerns about Apple-Alibaba deal

The Trump administration and congressional officials are scrutinizing a deal between Apple and Alibaba that would bring Alibaba-powered AI features to iPhones sold in China, according to The New York Times. Citing anonymous sources, the NYT says White House officials and members of the House Select Committee on China have asked Apple executives directly about…

New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors

Cybersecurity researchers are calling attention to a new botnet malware called HTTPBot that has been used to primarily single out the gaming industry, as well as technology companies and educational institutions in China. “Over the past few months, it has expanded aggressively, continuously leveraging infected devices to launch external attacks,” NSFOCUS said in a report…

Breachforums Boss to Pay $700k in Healthcare Breach

In what experts are calling a novel legal outcome, the 22-year-old former administrator of the cybercrime community Breachforums will forfeit nearly $700,000 to settle a civil lawsuit from a health insurance company whose customer data was posted for sale on the forum in 2023. Conor Brian Fitzpatrick, a.k.a. “Pompompurin,” is slated for resentencing next month…

Foxconn gets nod for $435M project to make more of Apple chips in India, eventually

Foxconn, a key manufacturer for Apple, has received an approval from India’s cabinet to build a new 37 billion Indian rupees ($435 million) semiconductor plant in a joint venture with the country’s IT giant HCL Group. The deal is the latest move to reduce Apple’s reliance on China and produce more components in India. The…

DHS won’t tell Congress how many people it’s cut from CISA

The Department of Homeland Security won’t tell Congress how many employees at the Cybersecurity and Infrastructure Security Agency it has fired or pushed to leave, a top congressional Democrat said Wednesday. “You’ve overseen mass reductions in the workforce at CISA and” the Federal Emergency Management Agency, Mississippi Rep. Bennie Thompson, the top Democrat on the…

China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide

A recently disclosed critical security flaw impacting SAP NetWeaver is being exploited by multiple China-nexus nation-state actors to target critical infrastructure networks. “Actors leveraged CVE-2025-31324, an unauthenticated file upload vulnerability that enables remote code execution (RCE),” EclecticIQ researcher Arda Büyükkaya said in an analysis published today. Targets of the campaign

Apple reportedly plans to hike prices of upcoming iPhones

Apple is planning to increase the prices of its iPhone lineup set to launch this autumn, though it is trying not to make it seem as if the hikes are connected to the U.S.’ tariffs on imports from China, The Wall Street Journal reported, citing anonymous sources. The company is considering instead linking the price…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Tech stocks look set to jump as U.S. and China pause reciprocal tariffs

U.S. tech stocks, along with the broader stock markets, seemed ready to start the day with a high, as the United States and China on Monday agreed to temporarily cut reciprocal tariffs for 90 days. Per the deal, reached in Geneva, the U.S. would temporarily shelve the 145% reciprocal tariff on goods imported from China,…

Senators move to quash the use of Chinese AI system by federal contractors 

A bipartisan Senate bill would formally ban the use of DeepSeek by federal contractors, part of a larger effort to keep the Chinese-made large language model out of government systems and networks, where lawmakers fear it could pose cybersecurity and national security concerns. The bill, introduced by Sens. Bill Cassidy, R-La., and Jacky Rosen, D-Nev.,…

Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell

A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently disclosed security flaw in SAP NetWeaver. Forescout Vedere Labs, in a report published Thursday, said it uncovered a malicious infrastructure likely associated with the hacking group weaponizing CVE-2025-31324 (CVSS score: 10.0) since April 29, 2025. CVE-2025-31324 refers to a critical SAP NetWeaver…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Hackers booby trap NPM with cross-language imposter packages

Hackers are abusing the Node Package Manager (NPM) registry — a database of JavaScript packages — to target multi-language developers with typo-squatted packages containing stealers and remote code execution (RCE) codes. According to a research by cybersecurity firm Socket, a coordinated malware campaign, with evidence of origin in China, has published dozens of malicious packages…

Quantum supremacy: Cybersecurity’s ultimate arms race has China way in front

Imagine a vast, ancient library, the Library of All Secrets. Within its countless shelves reside every code, message, and hidden truth ever recorded. For centuries, these secrets have been safe, locked away behind intricate, almost unbreakable locks. Now picture a new kind of key, shimmering and ethereal, called the “Quantum Key.” Unlike ordinary keys, this…

House appropriators have reservations — or worse — about proposed CISA cuts

House appropriators on Tuesday challenged proposed budget cuts for the Cybersecurity and Infrastructure Security Agency, with Democrats saying the Trump administration was disturbingly moving money away from the agency and a key Republican saying he needed to see justifications for the reductions. The Trump administration has proposed cutting CISA funding by $491 million, and some…

Anthropic suggests tweaks to proposed U.S. AI chip export controls

Anthropic agrees with the U.S. government that implementing robust export controls on domestic-made AI chips will help the U.S. compete in the AI race against China. But the company is suggesting a few tweaks to the proposed restrictions. Anthropic released a blog post on Wednesday stating that the company “strongly supports” the U.S. Department of…

Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool

A China-aligned advanced persistent threat (APT) group called TheWizards has been linked to a lateral movement tool called Spellbinder that can facilitate adversary-in-the-middle (AitM) attacks. “Spellbinder enables adversary-in-the-middle (AitM) attacks, through IPv6 stateless address autoconfiguration (SLAAC) spoofing, to move laterally in the compromised network, intercepting packets and

U.S. Companies Honed Their Surveillance Tech in Israel. Now It’s Coming Home.

Illustration: The Intercept In partnership with Rita Murad, a 21-year-old Palestinian citizen of Israel and student at the Technion Israel Institute of Technology, was arrested by Israeli authorities in November 2023 after sharing three Instagram stories on the morning of October 7. The images included a picture of a bulldozer breaking through the border fence in Gaza…

RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed Control

Cybersecurity researchers have revealed that RansomHub’s online infrastructure has “inexplicably” gone offline as of April 1, 2025, prompting concerns among affiliates of the ransomware-as-a-service (RaaS) operation. Singaporean cybersecurity company Group-IB said that this may have caused affiliates to migrate to Qilin, given that “disclosures on its DLS [data leak site] have doubled since

DHS Secretary Noem: CISA needs to get back to ‘core mission’

SAN FRANCISCO — Homeland Security Secretary Kristi Noem outlined her plans Tuesday to refocus the Cybersecurity and Infrastructure Security Agency (CISA) on protecting critical infrastructure from increasingly sophisticated threats — particularly from China — while distancing the agency from what she characterized as mission drift under previous leadership. Speaking at the 2025 RSAC Conference, Noem…