/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Report: China is altering its critical vulnerability disclosure database, backdating disclosure times of vulnerabilities that government hackers may want to use

Chinese intelligence agencies are doctoring the Chinese National Vulnerabilities Database (CNNVD) to hide security flaws …

BleepingComputer.com Catalin Cimpanu

Context & Ripple Effects

The disclosure pipeline Beijing built has been documented step by step in this coverage: a 2021 law requiring companies to hand flaws to the government within two days gave Chinese intelligence first look at vulnerabilities before vendors could patch them, and Microsoft later accused China-backed hackers of abusing those disclosure requirements to develop zero-days. A joint NSA-CISA-FBI advisory separately confirmed China-backed hackers exploiting publicly known flaws to snoop on network traffic.

This report marks an escalation: the database itself — the Chinese National Vulnerabilities Database — is allegedly being doctored, with disclosure times backdated so flaws appear older and less urgent than they are. That moves the concern from collection to falsification, and it lands amid broader opacity, with experts noting China's hacking breakthroughs have grown more secretive since the reporting mandates took effect.

First-order effects

  • Defenders and researchers who rely on CNNVD timestamps for triage can no longer trust how fresh a disclosed flaw really is, while government hackers gain a longer unpatched window on any vulnerability whose disclosure date was pushed back.

Second-order effects

  • Western vendors and CERTs are pushed toward treating CNNVD entries as unverified intelligence requiring independent confirmation, raising the cost of consuming Chinese-sourced vulnerability data — a dynamic Microsoft's earlier abuse accusation now reads as a warning shot for.

Third-order effects

  • If national vulnerability databases become instruments of state hacking operations, the shared global model of coordinated disclosure fragments into parallel, mutually distrusted feeds — an extension of the same logic behind the 2021 law, where mandatory reporting turned defensive infrastructure into offensive stockpiling.

The trend: National vulnerability databases are shifting from shared defensive infrastructure to contested instruments of state cyber operations, with each disclosure mandate widening the gap between what governments know and what defenders can verify.