/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

CISA: hacking groups linked to China's Ministry of State Security have exploited F5, Citrix, Pulse Secure, and Microsoft Exchange bugs to hack US gov't networks

Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity Ravie Lakshmanan / The Hacker News : CISA: Chinese Hackers Exploiting Unpatched Devices to Target U.S. Agencies Ken Wieland / Light Reading : US agency red flags Chinese state-affiliated cyberattacks Ionut Arghire / SecurityWeek : Chinese Hackers Using Publicly Available Resources in Attacks on U.S. Government Lindsey O'Donnell / Threatpost : Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs Mariam Baksh / Nextgov : Hackers Connected to China Have Compromised U.S. Government Systems, CISA says Tweets: Florian Roth / @cyb3rops : While newbie hackers believe that the front line runs between “the community and vendors” (I blame MrRobot&the EvilCorp theme), the actual&relevant battle has been fought between companies that create&preserve our prosperity & foreign actors that stole it https://us-cert.cisa.gov/... https://twitter.com/... Us-Cert / @uscert_gov : 🚨 @CISAgov and @FBI issued an advisory on Chinese Ministry of State Security-affiliated cyber threat activity. Protect your network and information systems by regularly applying the latest security patches & updates. Read more at https://us-cert.cisa.gov/.... #Cybersecurity #InfoSec https://twitter.com/... Bad Packets / @bad_packets : Bad Packets initial vulnerability scans (post-public disclosure) found: • 14,500 Pulse Secure VPN servers vulnerable to CVE-2019-11510 • 25,000 Citrix (NetScaler) servers vulnerable to CVE-2019-19781 • 3,000 BIG-IP F5 servers vulnerable to CVE-2020-5902 https://twitter.com/... @cisagov : Today we published an advisory with @FBI about open source information and common exploits used for malicious activity by Chinese MSS affiliated cyber actors. Learn how to strengthen network defense and reduce exposure: https://us-cert.cisa.gov/.... #Cybersecurity #NationalSecurity https://twitter.com/... Catalin Cimpanu / @campuscodi : Some of these attacks have been successful, per CISA (see table below). But the CISA advisory goes beyond attacks on networking gear. It also includes common TTPs and MITRE ATT&CK identifiers used by Chinese actors in general. More in the alert, here: https://us-cert.cisa.gov/... https://twitter.com/... Kevin Beaumont / @gossithedog : Many of these date back 12 months or more, I recommend checking your network boundaries. If you don't know what your network boundaries IP ranges are, search for your org on https://shodan.io/ and such to find out. https://twitter.com/...

ZDNet Catalin Cimpanu

Context & Ripple Effects

This CISA-FBI advisory lands mid-pattern: two years earlier the FBI had caught nation-state hackers breaching two US municipalities through a SharePoint flaw that was already patched, and the same playbook — publicly known vulnerabilities left unpatched on internet-facing appliances — recurs here against F5 BIG-IP, Citrix, Pulse Secure, and Microsoft Exchange, with CVE-2019-11510 and CVE-2020-5902 among the cited entry points.

What makes the attribution notable is the actor: groups tied to China's Ministry of State Security, not criminal crews, treating commodity edge-device bugs as espionage infrastructure. The related coverage shows this is not episodic — it extends through a later [[a:979629|joint NSA-CISA-FBI advisory on China-backed hackers exploiting known vulns to snoop network traffic]], Microsoft's disclosures on compromised critical-infrastructure organizations and month-long access to government email, and ultimately the Salt Typhoon intrusions into US ISPs.

First-order effects

  • US government networks running unpatched F5, Citrix, Pulse Secure, or Exchange gear face immediate remediation pressure, since CISA has confirmed these are active exploitation paths rather than theoretical risk.
  • The four vendors are now named in a federal attribution statement, putting their enterprise and government customers on notice that their appliances are the preferred Chinese espionage front door.

Second-order effects

  • Federal buyers begin weighing appliance vendors by patch discipline and end-of-life exposure, shifting procurement weight toward products with faster security response — and the 2022 joint advisory confirms the exploitation pattern persisted long enough to force repeated interagency responses.
  • Security teams redirect budget from perimeter VPN appliances toward monitoring and zero-trust architectures, because the advisory shows the attack surface lives on devices most orgs treat as plumbing.

Third-order effects

  • If the pattern holds — patched-but-unpatched-in-practice edge devices as the standard state-espionage vector — US policy drifts from per-advisory warnings toward mandatory patching timelines and retirement of legacy remote-access gear across government networks.
  • Joint CISA-FBI-NSA advisories harden into the standing instrument of US cyber defense, with each attribution raising the political cost for Beijing-linked operations targeting civilian infrastructure.

The trend: Chinese state-sponsored espionage is converging on unpatched edge and remote-access infrastructure as its primary US entry point, met by an escalating cadence of joint federal advisories that stretches from municipal breaches in 2020 to telecom-scale intrusions like Salt Typhoon.

Discussion

  • @cyb3rops Florian Roth on x
    While newbie hackers believe that the front line runs between “the community and vendors” (I blame MrRobot&the EvilCorp theme), the actual&relevant battle has been fought between companies that create&preserve our prosperity & foreign actors that stole it https://us-cert.cisa.gov…
  • @uscert_gov Us-Cert on x
    🚨 @CISAgov and @FBI issued an advisory on Chinese Ministry of State Security-affiliated cyber threat activity. Protect your network and information systems by regularly applying the latest security patches & updates. Read more at https://us-cert.cisa.gov/.... #Cybersecurity #Info…
  • @bad_packets Bad Packets on x
    Bad Packets initial vulnerability scans (post-public disclosure) found: • 14,500 Pulse Secure VPN servers vulnerable to CVE-2019-11510 • 25,000 Citrix (NetScaler) servers vulnerable to CVE-2019-19781 • 3,000 BIG-IP F5 servers vulnerable to CVE-2020-5902 https://twitter.com/...
  • @cisagov @cisagov on x
    Today we published an advisory with @FBI about open source information and common exploits used for malicious activity by Chinese MSS affiliated cyber actors. Learn how to strengthen network defense and reduce exposure: https://us-cert.cisa.gov/.... #Cybersecurity #NationalSecuri…
  • @campuscodi Catalin Cimpanu on x
    Some of these attacks have been successful, per CISA (see table below). But the CISA advisory goes beyond attacks on networking gear. It also includes common TTPs and MITRE ATT&CK identifiers used by Chinese actors in general. More in the alert, here: https://us-cert.cisa.gov/...…
  • @gossithedog Kevin Beaumont on x
    Many of these date back 12 months or more, I recommend checking your network boundaries. If you don't know what your network boundaries IP ranges are, search for your org on https://shodan.io/ and such to find out. https://twitter.com/...