Geek-Guy.com

Category: Asia Pacific

SentinelOne Uncovers Chinese Espionage Campaign Targeting Its Infrastructure and Clients

Cybersecurity company SentinelOne has revealed that a China-nexus threat cluster dubbed PurpleHaze conducted reconnaissance attempts against its infrastructure and some of its high-value customers. “We first became aware of this threat cluster during a 2024 intrusion conducted against an organization previously providing hardware logistics services for SentinelOne employees,” security

House passes bill to study routers’ national security risks

A bill requiring the Department of Commerce to study national security issues posed by routers and modems controlled by U.S. adversaries passed the House on Monday, advancing legislation that lawmakers say is “crucial” to understanding the devices’ cybersecurity risks. The House has moved quickly on the Removing Our Unsecure Technologies to Ensure Reliability and Security…

Erodiert die Security-Reputation der USA?

Trump stiftet Verunsicherung – auch wenn’s um Cybersicherheit geht. Joshua Sukoff | shutterstock.com Nachdem US-Präsident Donald Trump nun auch Cybersicherheitsunternehmen per Executive Order für abweichende politische Positionen abstraft, befürchten nicht wenige Branchenexperten, dass US-Sicherheitsunternehmen künftig ähnlich in Verruf geraten könnten wie ihre russischen und chinesischen Konkurrenten. Die zentralen Fragen sind dabei: Können sich CISOs beziehungsweise…

AI can help defenders stop nation-state threat actors at machine speed

Last year, the escalating concerns about Chinese threat actors breaching U.S. organizations reached a crescendo as federal authorities issued increasingly urgent advisories about China’s “Typhoon” groups infiltrating U.S. networks, pressing organizations to take immediate action. The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) warned that these groups were engaged…

Outside experts pick up the slack on safety testing on OpenAI’s newest model release

GPT-4.1, the latest family of generative AI models from OpenAI, was released earlier this month with promised improvements around coding, instruction following and context. It’s also the first model released by the company since it announced changes to the way it tests and evaluates products for safety. Unlike its previous fine-tuned models, OpenAI did not…

Chinese APT Billbug deploys new malware toolset in attack on multiple sectors

Chinese cyberespionage group Billbug has revamped its attack toolkit with new malware payloads in a wide-reaching campaign targeting multiple organizations in Southeast Asia. The new tools, which include credential stealers, a reverse shell, and an updated backdoor, were observed in attacks that lasted from August to February. “Targets included a government ministry, an air traffic…

A Chinese AI video startup appears to be blocking politically sensitive images

A China-based startup, Sand AI, has released an openly licensed video-generating AI model that’s garnered praise from entrepreneurs like Microsoft Research Asia founding director Kai-Fu Lee. But Sand AI appears to be censoring images that might raise the ire of Chinese regulators from the hosted version of the model, according to TechCrunch’s testing. Earlier this…

Rebuilding Maritime Cybersecurity Resilience: Charting an America First Course to Secure the U.S. Homeland

U.S. ports are vital to the flow of imports and exports; however, the entire maritime transportation system’s cybersecurity is exceedingly vulnerable. The August 2024 ransomware attack at the Port of Seattle resulted in significant cargo delays and a data breach of 90,000 individuals. Such a wide-scale incursion could have resulted in a longer loss of…

Lotus Panda Hacks SE Asian Governments With Browser Stealers and Sideloaded Malware

The China-linked cyber espionage group tracked as Lotus Panda has been attributed to a campaign that compromised multiple organizations in an unnamed Southeast Asian country between August 2024 and February 2025. “Targets included a government ministry, an air traffic control organization, a telecoms operator, and a construction company,” the Symantec Threat Hunter Team said in…

Will politicization of security clearances make US cybersecurity firms radioactive?

With the US government now tying security clearances to the support of specific political positions, many in the security community fear it may tar US vendors with the same brush as their Russian and Chinese counterparts. Will enterprise CISOs now have to worry about whether they can rely on American threat intel? More broadly, will…

Chinese shopping app Taobao joins DHgate in Top 5 on US App Store

The Chinese e-commerce marketplace app DHgate, which is now the No. 2 free iPhone app in the U.S., isn’t the only one that’s oddly benefiting from President Trump’s tariffs on U.S. imports from China. Another Chinese shopping app, Taobao, has now also entered the Top 5 as of Thursday. U.S. consumers began flocking to these…

Automakers selling cars in China banned from using ‘autonomous driving’ in ads

China is cracking down on how automakers advertise driver assistance features, banning terms like “autonomous driving,” “self-driving,” and “smart driving,” Reuters reported, citing a transcript of a meeting between the government and industry representatives. The updated rule will also prohibit automakers from rolling out improvements via software updates to advanced driving assistance systems in vehicles…

House investigation into DeepSeek teases out funding, security realities around Chinese AI tool

A House panel has concluded that the U.S. government should double down on export controls and other tools to slow down the progress of Chinese AI companies like DeepSeek, while also preparing for a future where those efforts fail. In a report released Wednesday, the House Select Committee on the Chinese Communist Party further fleshes…

Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates

The China-linked threat actor known as Mustang Panda has been attributed to a cyber attack targeting an unspecified organization in Myanmar with previously unreported tooling, highlighting continued effort by the threat actors to increase the sophistication and effectiveness of their malware. This includes updated versions of a known backdoor called TONESHELL, as well as a…

Shein and Temu to raise prices for US shoppers in response to tariffs

Temu and Shein plan to raise prices for U.S. customers starting next week on April 25th, due to President Donald Trump’s tariffs on goods shipped from China, the Associated Press reports. The 145% tariff on products made in China, along with Trump’s decision to end a customs exemption that had allowed goods under $800 to…

35 countries use Chinese networks for transporting mobile user traffic, posing cyber risks

U.S. allies are among the 35 countries where mobile providers employ China-based networks for transporting user traffic, opening travelers and residents in those nations to potential surveillance, an analysis published Thursday concludes. “Everyone knows that they have to be careful with their phones when they travel to China,” Rocky Cole, chief operating officer at iVerify,…

Trump administration reportedly considers a US DeepSeek ban

The Trump administration is considering new restrictions on the Chinese AI lab DeepSeek that would limit it from buying Nvidia’s AI chips, and potentially bar Americans from accessing its AI services, The New York Times reported on Wednesday. The restrictions are part of the Trump administration’s effort to compete with China on AI. Months after…

Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1

IntroductionThe Zscaler ThreatLabz team discovered new activity associated with Mustang Panda, originating from two machines from a targeted organization in Myanmar. This research led to the discovery of new ToneShell variants and several previously undocumented tools. Mustang Panda, a China-sponsored espionage group, traditionally targets government-related entities, military entities, minority groups, and non-governmental organizations (NGOs) primarily…

AMD estimates $800M charge on US license requirement for AI chips

AMD says that the U.S. government’s license control requirement for exporting AI chips to China and certain other countries may impact its earnings materially. If AMD doesn’t successfully obtain a license, the company could be on the hook for roughly $800 million in inventory, purchase commitments, and related reserves charges, the company said in a…

Exclusive: Peters, Rounds tee up bill to renew expiring cyber threat information sharing law

A bipartisan pair of senators are kicking off the race Wednesday to reauthorize a 2015 cyber threat information sharing law, a move that industry groups and cyber experts are eager to see happen before it’s set to expire in September. Advocates say the 10-year-old Cybersecurity Information Sharing Act has been vital to sharing threat information…

Überwachungssoftware infiziert gezielt Smartphones

Fingierte Messenger-Apps täuschen ihre Opfer und führen so freiwillig zur Installation der Schadsoftware. siro46 – shutterstock.com as Bundesamt für Verfassungsschutz und das britische National Cyber Security Centre warnen vor der Gefahr, die von den Schadprogrammen “Moonshine” und “BadBazaar” ausgeht. Dabei handelt es sich um zwei Varianten von Überwachungssoftware, die gezielt Smartphones infizieren, um sensible Daten zu sammeln.…

US government imposes license requirement on Nvidia H20 exports

Semiconductor giant Nvidia is facing unexpected new U.S. export controls on its H20 chips. In a filing Tuesday, Nvidia said it was informed by the U.S. government that it will need a license to export its H20 AI chips to China. This license will be required indefinitely, according to the filing — the U.S. government…

Nvidia H20 chip exports hit with license requirement by US government

Semiconductor giant Nvidia is facing unexpected new U.S. export controls on its H20 chips. In a filing Tuesday, Nvidia said it was informed by the U.S. government that it will need a license to export its H20 AI chips to China. This license will be required indefinitely, according to the filing — the U.S. government…

Chinese law enforcement places NSA operatives on wanted list over alleged cyberattacks

China stepped up its allegations of U.S. cyberattacks Tuesday, with local law enforcement saying they were investigating three National Security Agency operatives they had placed on a wanted list and a national official condemning the alleged attacks. State media outlet Xinhau advanced the claims in two stories, one detailing a hacking campaign during the Asian…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

The AI Fix #46: AI can read minds now, and is your co-host a clone?

In episode 46 of The AI Fix, China trolls US tariffs, a microscopic pogoing flea-bot makes a tiny leap forward for robotics, Google unveils the Agent2Agent protocol, a robot dog is so cute it ruins Graham’s entire day, and Europe commits €20 billion and all of its buzzwords to five moonshot AI gigafactories. Graham brings…

China alleges US cyber espionage during the Asian Winter Games, names 3 NSA agents

China has accused the US of conducting more than 170,000 cyberattacks against the Asian Winter Games held in Harbin this February. Officials have named three alleged NSA operatives they claim spearheaded the digital assault. The Harbin Public Security Bureau identified Katheryn A. Wilson, Robert J. Snelling, and Stephen W. Johnson as NSA personnel responsible for…

Trump Revenge Tour Targets Cyber Leaders, Elections

President Trump last week revoked security clearances for Chris Krebs, the former director of the Cybersecurity and Infrastructure Security Agency (CISA) who was fired by Trump after declaring the 2020 election the most secure in U.S. history. The White House memo, which also suspended clearances for other security professionals at Krebs’s employer SentinelOne, comes as…

38 consumer startup founders lobby over Trump tariffs: One faces a surprise $200K bill

Small businesses could be crushed under President Trump’s increased tariffs, according to an open letter by 38 female consumer product founders. While Trump paused his tariff increases for 90 days for various countries – setting the rate at 10% for now  –  China’s was raised to 145%, which includes the previous 20% levy. In the…

China-based SMS Phishing Triad Pivots to Banks

China-based purveyors of SMS phishing kits are enjoying remarkable success converting phished payment card data into mobile wallets from Apple and Google. Until recently, the so-called “Smishing Triad” mainly impersonated toll road operators and shipping companies. But experts say these groups are now directly targeting customers of international financial institutions, while dramatically expanding their cybercrime…

Nvidia’s H20 AI chips may be spared from export controls — for now

Nvidia CEO Jensen Huang appears to have struck a deal with the Trump administration to avoid export restrictions on the company’s H20 AI chips. The H20, the most advanced Nvidia-produced AI chip that can still be exported from the U.S. to China, was reportedly spared thanks to a promise from Huang to invest in new…

Treasury bureau notifies Congress that email hack was a ‘major’ cybersecurity incident

The Office of the Comptroller of the Currency has notified Congress that a February breach of its email system is classified as a major cybersecurity incident. The incident was first disclosed Feb. 26, though the OCC provided virtually no details at the time, only saying that it had resolved a security incident “involving an administrative…

Bill to study national security risks in routers passes House committee

A federal study into the national security risks posed by routers, modems and similar devices controlled by U.S. adversaries moved one step closer to law Tuesday by advancing out of the House Energy and Commerce Committee. The Removing Our Unsecure Technologies to Ensure Reliability and Security (ROUTERS) Act from Reps. Bob Latta, R-Ohio, and Robin…

Tech experts recommend full steam ahead on US export controls for AI

Technology experts pressed Congress to maintain export controls on semiconductor chips and other technologies, telling lawmakers Tuesday that the restrictions are among the most effective strategies to slow China and other rival countries in the AI race, thereby helping U.S. companies hold a competitive edge. Placing export controls on these technologies is not new: both…

Apple might import more iPhones from India to side-step China tariffs

Apple is considering importing more iPhones from India to side-step the 54% additional tariffs on goods imported from China that U.S. President Donald Trump announced last week, the Wall Street Journal reported, citing anonymous sources. The company sees this as a short-term measure while it seeks to negotiate with the Trump administration to get an…

Apple might import more iPhones from India to side-step China tariffs

Apple is considering importing more iPhones from India to side-step the 54% additional tariffs on goods imported from China that U.S. President Donald Trump announced last week, the Wall Street Journal reported, citing anonymous sources. The company sees this as a short-term measure while it seeks to negotiate with the Trump administration to get an…

Analyst says Apple, Tesla have biggest exposure to Trump’s tariffs

Wedbush Securities analyst Dan Ives slashed his price targets for Apple and Tesla over the weekend as President Trump’s tariffs threaten to disrupt both businesses.  “The tariff economic Armageddon unleashed by Trump is a complete disaster for Apple given its massive China production exposure,” Ives said in a warning note over the weekend. “In our…

China-Linked Earth Alux Uses VARGEIT and COBEACON in Multi-Stage Cyber Intrusions

Cybersecurity researchers have shed light on a new China-linked threat actor called Earth Alux that has targeted various key sectors such as government, technology, logistics, manufacturing, telecommunications, IT services, and retail in the Asia-Pacific (APAC) and Latin American (LATAM) regions. “The first sighting of its activity was in the second quarter of 2023; back then,…

After fake employees, fake enterprises are next hiring threat to corporate data

Chinese companies are trying to cut Taiwan’s lead in semiconductor technology by hiring away its best engineering talent through ‘front’ companies that hide their connections to China, the Taiwanese Ministry of Justice Investigation Bureau (MJIB) has alleged. In a dramatic crackdown on the practice last week, MJIB said its agents raided 11 Chinese companies in…

The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques

The cyberespionage techniques of Earth Alux, a China-linked APT group, are putting critical industries at risk. The attacks, aimed at the APAC and Latin American regions, leverage powerful tools and techniques to remain hidden while stealing sensitive data.

The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques

The cyberespionage techniques of Earth Alux, a China-linked APT group, are putting critical industries at risk. The attacks, aimed at the APAC and Latin American regions, leverage powerful tools and techniques to remain hidden while stealing sensitive data.

The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques

The cyberespionage techniques of Earth Alux, a China-linked APT group, are putting critical industries at risk. The attacks, aimed at the APAC and Latin American regions, leverage powerful tools and techniques to remain hidden while stealing sensitive data.

China Miéville says we shouldn’t blame science fiction for its bad readers

It’s been 25 years since China Miéville stepped into the literary spotlight with his novel “Perdido Street Station.” Combining elements of science fiction, fantasy, and horror, the novel introduced readers to the fantastically complex city of New Crobuzon, filled with insect-headed khepri, cactus-shaped cactacae, and terrifying slake moths that feed on their victims’ dreams. It…

Commerce limits 19 Chinese, Taiwanese companies from buying U.S. tech

The Commerce Department plans to finalize economic sanctions this week on nearly 20 Chinese and Taiwanese organizations, citing the need to limit their access to U.S. cloud, artificial intelligence and quantum computing technologies. The sanctions, which will be detailed and published Friday in the Federal Register , would place additional license requirements on, and limit…

SpaceX reportedly has a secret backdoor for Chinese investment

Elon Musk’s rocket company SpaceX has allowed Chinese investors to buy stakes as long as the funds are routed through the Cayman Islands or other offshore hubs, according to reporting from ProPublica.  SpaceX is a defense contractor for the Pentagon, one that handles sensitive work like building a classified spy satellite network. Investment from China…

Microsoft launches AI agents to automate cybersecurity amid rising threats

Microsoft has introduced a new set of AI agents for its Security Copilot platform, designed to automate key cybersecurity functions as organizations face increasingly complex and fast-moving digital threats. The new tools focus on tasks such as phishing detection, data protection, and identity management — areas where attackers continue to exploit vulnerabilities at scale. AI…

Arrests in Tap-to-Pay Scheme Powered by Phishing

Authorities in at least two U.S. states last week independently announced arrests of Chinese nationals accused of perpetrating a novel form of tap-to-pay fraud using mobile devices. Details released by authorities so far indicate the mobile wallets being used by the scammers were created through online phishing scams, and that the accused were relying on…

FCC’s Carr alleges Chinese companies are making ‘end run’ around Chinese telecom bans, announces investigation 

The first initiative from The Federal Communications Commission’s newly-created Council on National Security will be a “sweeping” investigation of Chinese-made equipment in America’s telecommunications infrastructure, the agency announced Friday. In particular, FCC Commissioner Brendan Carr said the focus will be on equipment and services from Chinese companies already barred from U.S. networks under the Secure…

AI’s answers on China differ depending on the language, analysis finds

It’s well-established that AI models developed by Chinese AI labs like DeepSeek censor certain politically sensitive topics. A 2023 measure passed by China’s ruling party forbids models from generating content that “damages the unity of the country and social harmony.” According to one study, DeepSeek’s R1 refuses to answer 85% of questions about subjects deemed…

Rimini Street honoured with Multiple Consecutive ‘Great Place to Work’ certifications and ‘leadership Award’ Across Asia, Europe and North America

Rimini Street employees in Israel, Japan, Korea, Singapore, UK and USA celebrate the company’s commitment to an extraordinary workplace culture of fairness and togetherness COMPANY NEWS: Rimini Street, a global provider of end-to-end enterprise software support and innovation solutions, and the leading third-party support provider for Oracle, SAP and VMware software, today announced it has…

Six Governments Likely Use Israeli Paragon Spyware to Hack IM Apps and Harvest Data

The governments of Australia, Canada, Cyprus, Denmark, Israel, and Singapore are likely customers of spyware developed by Israeli company Paragon Solutions, according to a new report from The Citizen Lab. Paragon, founded in 2019 by Ehud Barak and Ehud Schneorson, is the maker of a surveillance tool called Graphite that’s capable of harvesting sensitive data…

DOGE to Fired CISA Staff: Email Us Your Personal Data

A message posted on Monday to the homepage of the U.S. Cybersecurity & Infrastructure Security Agency (CISA) is the latest exhibit in the Trump administration’s continued disregard for basic cybersecurity protections. The message instructed recently-fired CISA employees to get in touch so they can be rehired and then immediately placed on leave, asking employees to…

Unpatched Windows Zero-Day Flaw Exploited by 11 State-Sponsored Threat Groups Since 2017

An unpatched security flaw impacting Microsoft Windows has been exploited by 11 state-sponsored groups from China, Iran, North Korea, and Russia as part of data theft, espionage, and financially motivated campaigns that date back to 2017. The zero-day vulnerability, tracked by Trend Micro’s Zero Day Initiative (ZDI) as ZDI-CAN-25373, refers to an issue that allows…

Who is sending those scammy text messages about unpaid tolls?

It’s not just you.  Seemingly everyone is getting those text messages that serve as a notification of an unpaid toll road violation. The past due is usually less than $25, but is often paired with threats of excessive penalties, suspended vehicle registrations and threats to report the fare to state motor vehicle agencies. None of…

FCC creates national security council to counter cyber threats from China

The Federal Communications Commission (FCC) has established a new Council for National Security to coordinate and strengthen the agency’s efforts against foreign adversaries, with a particular focus on threats from China. “The Council will leverage the full range of the Commission’s regulatory, investigatory, and enforcement authorities to promote America’s national security and counter foreign adversaries,…

China is reportedly keeping DeepSeek under close watch

China appears to think homegrown AI startup DeepSeek could become a notable tech success story for the country.  After DeepSeek’s sudden rise to fame in January with the release of its open “reasoning” model, R1, the company is now operating under new, tighter government-influenced restrictions, according to The Information. Some of the company’s employees have…

OpenAI calls DeepSeek ‘state-controlled,’ calls for bans on ‘PRC-produced’ models

In a new policy proposal, OpenAI describes Chinese AI lab DeepSeek as “state-subsidized” and “state-controlled,” and recommends that the U.S. government consider banning models from the outfit and similar People’s Republic of China (PRC)-supported operations. The proposal, a submission for the Trump Administration’s “AI Action Plan” initiative, claims that DeepSeek’s models, including its R1 “reasoning” model,…

Singapore grants bail for Nvidia chip smugglers in alleged $390M fraud

A judge in Singapore granted bail to three men suspected of deceiving suppliers of server computers that may contain Nvidia chips affected by U.S. export rules that bar the sale of them to certain countries, as a route to halting them being sold to organizations in China. The move comes nearly two weeks after the…

Chinese Hackers Breach Juniper Networks Routers With Custom Backdoors and Rootkits

The China-nexus cyber espionage group tracked as UNC3886 has been observed targeting end-of-life MX routers from Juniper Networks as part of a campaign designed to deploy custom backdoors, highlighting their ability to focus on internal networking infrastructure. “The backdoors had varying custom capabilities, including active and passive backdoor functions, as well as an embedded script…

Salesforce to invest $1B in Singapore to boost adoption of AI

Salesforce plans to invest $1 billion in Singapore over the next five years as it seeks to fuel the adoption of its AI agent development platform, Agentforce. Salesforce claimed that Agentforce can help alleviate Singapore’s ongoing labor issues and augment the country’s workforce and enterprises by creating “digital workforces” that combine humans with autonomous AI…

Silk Typhoon Hackers Indicted

Lots of interesting details in the story: The US Department of Justice on Wednesday announced the indictment of 12 Chinese individuals accused of more than a decade of hacker intrusions around the world, including eight staffers for the contractor i-Soon, two officials at China’s Ministry of Public Security who allegedly worked with them, and two…

CISOs müssen OT-Risiken stärker adressieren

Da Angriffe auf OT-Bereiche zunehmen, sollten CISOs einen Exposure-Management-Ansatz verfolgen. Summit Art Creations – Shutterstock.com Die Bedrohungen gegen die Betriebstechnik (Operational Technology, OT) der kritischen Infrastruktur (KRITIS) verschärfen sich kontinuierlich. China baut offensive Komponenten in amerikanische Militär- und Unternehmensnetzwerke ein. Zudem haben chinesische Hacker Telekommunikationsunternehmen und Internetdienstleister infiltriert, um Zivilisten auszuspionieren. Seit etlichen Jahren, also…