The Atlantic Council details how a Chinese law from 2021 requiring companies to disclose flaws within two days of discovery helps China's hacking operations
Some foreign companies may be complying—potentially offering China's spies hints for hacking their customers. X: @a_greenberg , @a_greenberg , @a_greenberg , and @a_greenberg X: Andy Greenberg / @a_greenberg : The researchers show how China's web portal for uploading bug reports demands detailed information for how to exploit those bugs, and how reports are then made available to China's Ministry of State Security and orgs associated with People's Liberation Army hacking operations. Andy Greenberg / @a_greenberg : I reached out to all six firms: Beckhoff, D-Link, KUKA, Omron, Phoenix Contact, and Schneider Electric. You can read their responses (some flat-out denials, some more complicated/ambiguous reply statements) in the piece above. Andy Greenberg / @a_greenberg : The researchers also found a WeChat post from the Chinese government agency that collects the reports crediting six foreign tech firms (among others) for “passing examination,” possibly indicating they complied with the vulnerability disclosure law. Andy Greenberg / @a_greenberg : Chinese law demands tech firms operating there report hackable (unpatched) bugs in their products to the government within 2 days. An Atlantic Council report shows how firms seem to be complying—and how that helps China's hackers target their customers. https://www.wired.com/...
Context & Ripple Effects
China’s vulnerability-reporting regime has drawn earlier scrutiny: Microsoft alleged that China-backed actors used disclosure requirements to identify and develop zero-days, while reporting had already raised concerns about changes to China’s critical-vulnerability database.
The Atlantic Council’s findings add operational detail to that pattern: foreign firms may be feeding exploit-ready reports into a portal accessible to the Ministry of State Security and PLA-linked organizations. That connects disclosure compliance directly to the state-sponsored hacking ecosystem described in coverage of China’s growing reliance on private-sector hacking capacity.
First-order effects
- Foreign firms subject to the rule face a conflict between local compliance and protecting customers from exposure of unpatched flaws; several named companies disputed or did not clearly address whether they comply.
- China’s security and military-linked hacking organizations can receive detailed, potentially exploitable vulnerability information before public remediation is available.
Second-order effects
- Customers of affected suppliers may face a narrower window to patch or mitigate flaws if reports reach state-linked operators before fixes are broadly deployed.
- Security researchers and multinational vendors may reassess how they disclose vulnerabilities in China, particularly after Microsoft’s earlier allegation of disclosure rules being used to develop zero-days.
Third-order effects
- If this reporting channel remains tied to intelligence access, vulnerability disclosure becomes a strategic cyber-intelligence asset rather than solely a defensive coordination mechanism.
- The pattern could deepen fragmentation in global vulnerability handling, with vendors weighing national reporting mandates against coordinated disclosure and customer protection.
The trend: This is part of the broader trend of states treating vulnerability intelligence and software-security reporting as dual-use strategic infrastructure.