CISA: hacking groups linked to China's Ministry of State Security have exploited F5, Citrix, Pulse Secure, and Microsoft Exchange bugs to hack US gov't networks
Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity Ravie Lakshmanan / The Hacker News : CISA: Chinese Hackers Exploiting Unpatched Devices to Target U.S. Agencies Ken Wieland / Light Reading : US agency red flags Chinese state-affiliated cyberattacks Ionut Arghire / SecurityWeek : Chinese Hackers Using Publicly Available Resources in Attacks on U.S. Government Lindsey O'Donnell / Threatpost : Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs Mariam Baksh / Nextgov : Hackers Connected to China Have Compromised U.S. Government Systems, CISA says Tweets: Florian Roth / @cyb3rops : While newbie hackers believe that the front line runs between “the community and vendors” (I blame MrRobot&the EvilCorp theme), the actual&relevant battle has been fought between companies that create&preserve our prosperity & foreign actors that stole it https://us-cert.cisa.gov/... https://twitter.com/... Us-Cert / @uscert_gov : 🚨 @CISAgov and @FBI issued an advisory on Chinese Ministry of State Security-affiliated cyber threat activity. Protect your network and information systems by regularly applying the latest security patches & updates. Read more at https://us-cert.cisa.gov/.... #Cybersecurity #InfoSec https://twitter.com/... Bad Packets / @bad_packets : Bad Packets initial vulnerability scans (post-public disclosure) found: • 14,500 Pulse Secure VPN servers vulnerable to CVE-2019-11510 • 25,000 Citrix (NetScaler) servers vulnerable to CVE-2019-19781 • 3,000 BIG-IP F5 servers vulnerable to CVE-2020-5902 https://twitter.com/... @cisagov : Today we published an advisory with @FBI about open source information and common exploits used for malicious activity by Chinese MSS affiliated cyber actors. Learn how to strengthen network defense and reduce exposure: https://us-cert.cisa.gov/.... #Cybersecurity #NationalSecurity https://twitter.com/... Catalin Cimpanu / @campuscodi : Some of these attacks have been successful, per CISA (see table below). But the CISA advisory goes beyond attacks on networking gear. It also includes common TTPs and MITRE ATT&CK identifiers used by Chinese actors in general. More in the alert, here: https://us-cert.cisa.gov/... https://twitter.com/... Kevin Beaumont / @gossithedog : Many of these date back 12 months or more, I recommend checking your network boundaries. If you don't know what your network boundaries IP ranges are, search for your org on https://shodan.io/ and such to find out. https://twitter.com/...
Context & Ripple Effects
This CISA-FBI advisory lands mid-pattern: two years earlier the FBI had caught nation-state hackers breaching two US municipalities through a SharePoint flaw that was already patched, and the same playbook — publicly known vulnerabilities left unpatched on internet-facing appliances — recurs here against F5 BIG-IP, Citrix, Pulse Secure, and Microsoft Exchange, with CVE-2019-11510 and CVE-2020-5902 among the cited entry points.
What makes the attribution notable is the actor: groups tied to China's Ministry of State Security, not criminal crews, treating commodity edge-device bugs as espionage infrastructure. The related coverage shows this is not episodic — it extends through a later [[a:979629|joint NSA-CISA-FBI advisory on China-backed hackers exploiting known vulns to snoop network traffic]], Microsoft's disclosures on compromised critical-infrastructure organizations and month-long access to government email, and ultimately the Salt Typhoon intrusions into US ISPs.
First-order effects
- US government networks running unpatched F5, Citrix, Pulse Secure, or Exchange gear face immediate remediation pressure, since CISA has confirmed these are active exploitation paths rather than theoretical risk.
- The four vendors are now named in a federal attribution statement, putting their enterprise and government customers on notice that their appliances are the preferred Chinese espionage front door.
Second-order effects
- Federal buyers begin weighing appliance vendors by patch discipline and end-of-life exposure, shifting procurement weight toward products with faster security response — and the 2022 joint advisory confirms the exploitation pattern persisted long enough to force repeated interagency responses.
- Security teams redirect budget from perimeter VPN appliances toward monitoring and zero-trust architectures, because the advisory shows the attack surface lives on devices most orgs treat as plumbing.
Third-order effects
- If the pattern holds — patched-but-unpatched-in-practice edge devices as the standard state-espionage vector — US policy drifts from per-advisory warnings toward mandatory patching timelines and retirement of legacy remote-access gear across government networks.
- Joint CISA-FBI-NSA advisories harden into the standing instrument of US cyber defense, with each attribution raising the political cost for Beijing-linked operations targeting civilian infrastructure.
The trend: Chinese state-sponsored espionage is converging on unpatched edge and remote-access infrastructure as its primary US entry point, met by an escalating cadence of joint federal advisories that stretches from municipal breaches in 2020 to telecom-scale intrusions like Salt Typhoon.