In a joint cybersecurity advisory, the NSA, CISA, and the FBI reveal China-backed hackers exploited publicly known vulnerabilities to snoop on network traffic
Several US federal agencies today revealed that Chinese-backed threat actors have targeted and compromised major telecommunications companies … Source: National Security … .
Major telecommunications companies are put on notice that publicly disclosed vulnerabilities can provide China-backed actors access to network traffic, elevating remediation of known flaws in exposed infrastructure.
NSA, CISA, and the FBI align public attribution and defensive guidance around a shared threat to telecom operators rather than isolated agency or enterprise incidents.
Government customers and officials relying on carrier networks gain a stronger basis to treat telecom compromise as a communications-security risk, not solely a provider-level incident.
Third-order effects
Repeated use of known vulnerabilities against carriers points toward telecom infrastructure being defended as sovereign network substrate, with vulnerability management becoming part of national-security resilience.
If multi-agency and multinational warnings continue to document the same campaign, telecom operators will face more coordinated expectations to share threat intelligence and harden common infrastructure.
The trend: China-linked cyber activity is making telecom networks a central arena for state-backed collection, pushing carrier security toward a more coordinated national-infrastructure model.
“This work is building the foundation that they can do all of their objectives,” @NSA_CSDirector said of Chinese state-linked hackers. “This is their plumbing.” https://therecord.media/...
“The attackers then stole credentials to access underlying SQL databases and used SQL commands to dump user and admin credentials from critical Remote Authentication Dial-In User Service (RADIUS) servers.” https://twitter.com/... https://twitter.com/...
PRC sponsored actors are using access to telcos and ISPs to scale their targeting. To kick them out, we must understand the tradecraft and detect them beyond just initial access. https://twitter.com/...
China-backed threat actors have exploited known vulnerabilities to conduct massive data harvesting operations against the US: https://www.bleepingcomputer.com/ ...
@FBI ... “Businesses may understand that they've had intrusion, or they've stopped an attempted intrusion, but they often can't weave together the pieces. This advisory is intended to bring together the pieces,” @NSA_CSDirector told me. https://therecord.media/...
The #China sponsored #cyber actors “are also consistently evolving & adapting tactics to bypass defenses” warn @CISAgov @NSACyber @FBI They “mix their customized toolset w/publicly available tools...to obscure their activity by blending into the noise” https://www.cisa.gov/...
Taking advantage of common vulnerabilities and exposures (CVEs) allows malicious actors backed by Beijing to break into victim accounts and network infrastructure —"without using their own distinctive or identifying malware," @FBI, @NSAGov & @CISAgov. https://therecord.media/...
It's almost like we need to really have that talk with vendors of critical infrastructure and tell them that something has to change. Looking at Cisas KEV, one realises how bad software still is given the bugs being exploited. https://twitter.com/...
At Black Hat in 2018, I had very sharp words with a guy whose job is to coordinate vulnerability disclosures for a big company, about this very issue. He told me that he trusted his (CN) vulnerability reporters implicitly. That dude was and is hopelessly naive. Magical thinking. …