/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The Atlantic Council details how a Chinese law from 2021 requiring companies to disclose flaws within two days of discovery helps China's hacking operations

Some foreign companies may be complying—potentially offering China's spies hints for hacking their customers. X: @a_greenberg , @a_greenberg , @a_greenberg , and @a_greenberg X: Andy Greenberg / @a_greenberg : The researchers show how China's web portal for uploading bug reports demands detailed information for how to exploit those bugs, and how reports are then made available to China's Ministry of State Security and orgs associated with People's Liberation Army hacking operations. Andy Greenberg / @a_greenberg : I reached out to all six firms: Beckhoff, D-Link, KUKA, Omron, Phoenix Contact, and Schneider Electric. You can read their responses (some flat-out denials, some more complicated/ambiguous reply statements) in the piece above. Andy Greenberg / @a_greenberg : The researchers also found a WeChat post from the Chinese government agency that collects the reports crediting six foreign tech firms (among others) for “passing examination,” possibly indicating they complied with the vulnerability disclosure law. Andy Greenberg / @a_greenberg : Chinese law demands tech firms operating there report hackable (unpatched) bugs in their products to the government within 2 days. An Atlantic Council report shows how firms seem to be complying—and how that helps China's hackers target their customers. https://www.wired.com/...

Wired Andy Greenberg

Context & Ripple Effects

China’s vulnerability-reporting regime has drawn earlier scrutiny: Microsoft alleged that China-backed actors used disclosure requirements to identify and develop zero-days, while reporting had already raised concerns about changes to China’s critical-vulnerability database.

The Atlantic Council’s findings add operational detail to that pattern: foreign firms may be feeding exploit-ready reports into a portal accessible to the Ministry of State Security and PLA-linked organizations. That connects disclosure compliance directly to the state-sponsored hacking ecosystem described in coverage of China’s growing reliance on private-sector hacking capacity.

First-order effects

  • Foreign firms subject to the rule face a conflict between local compliance and protecting customers from exposure of unpatched flaws; several named companies disputed or did not clearly address whether they comply.
  • China’s security and military-linked hacking organizations can receive detailed, potentially exploitable vulnerability information before public remediation is available.

Second-order effects

Third-order effects

  • If this reporting channel remains tied to intelligence access, vulnerability disclosure becomes a strategic cyber-intelligence asset rather than solely a defensive coordination mechanism.
  • The pattern could deepen fragmentation in global vulnerability handling, with vendors weighing national reporting mandates against coordinated disclosure and customer protection.

The trend: This is part of the broader trend of states treating vulnerability intelligence and software-security reporting as dual-use strategic infrastructure.