Geek-Guy.com

Category: Asia Pacific

Breachforums Boss to Pay $700k in Healthcare Breach

In what experts are calling a novel legal outcome, the 22-year-old former administrator of the cybercrime community Breachforums will forfeit nearly $700,000 to settle a civil lawsuit from a health insurance company whose customer data was posted for sale on the forum in 2023. Conor Brian Fitzpatrick, a.k.a. “Pompompurin,” is slated for resentencing next month…

Foxconn gets nod for $435M project to make more of Apple chips in India, eventually

Foxconn, a key manufacturer for Apple, has received an approval from India’s cabinet to build a new 37 billion Indian rupees ($435 million) semiconductor plant in a joint venture with the country’s IT giant HCL Group. The deal is the latest move to reduce Apple’s reliance on China and produce more components in India. The…

DHS won’t tell Congress how many people it’s cut from CISA

The Department of Homeland Security won’t tell Congress how many employees at the Cybersecurity and Infrastructure Security Agency it has fired or pushed to leave, a top congressional Democrat said Wednesday. “You’ve overseen mass reductions in the workforce at CISA and” the Federal Emergency Management Agency, Mississippi Rep. Bennie Thompson, the top Democrat on the…

China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide

A recently disclosed critical security flaw impacting SAP NetWeaver is being exploited by multiple China-nexus nation-state actors to target critical infrastructure networks. “Actors leveraged CVE-2025-31324, an unauthenticated file upload vulnerability that enables remote code execution (RCE),” EclecticIQ researcher Arda Büyükkaya said in an analysis published today. Targets of the campaign

Tech stocks look set to jump as U.S. and China pause reciprocal tariffs

U.S. tech stocks, along with the broader stock markets, seemed ready to start the day with a high, as the United States and China on Monday agreed to temporarily cut reciprocal tariffs for 90 days. Per the deal, reached in Geneva, the U.S. would temporarily shelve the 145% reciprocal tariff on goods imported from China,…

Senators move to quash the use of Chinese AI system by federal contractors 

A bipartisan Senate bill would formally ban the use of DeepSeek by federal contractors, part of a larger effort to keep the Chinese-made large language model out of government systems and networks, where lawmakers fear it could pose cybersecurity and national security concerns. The bill, introduced by Sens. Bill Cassidy, R-La., and Jacky Rosen, D-Nev.,…

Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell

A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently disclosed security flaw in SAP NetWeaver. Forescout Vedere Labs, in a report published Thursday, said it uncovered a malicious infrastructure likely associated with the hacking group weaponizing CVE-2025-31324 (CVSS score: 10.0) since April 29, 2025. CVE-2025-31324 refers to a critical SAP NetWeaver…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Hackers booby trap NPM with cross-language imposter packages

Hackers are abusing the Node Package Manager (NPM) registry — a database of JavaScript packages — to target multi-language developers with typo-squatted packages containing stealers and remote code execution (RCE) codes. According to a research by cybersecurity firm Socket, a coordinated malware campaign, with evidence of origin in China, has published dozens of malicious packages…

Quantum supremacy: Cybersecurity’s ultimate arms race has China way in front

Imagine a vast, ancient library, the Library of All Secrets. Within its countless shelves reside every code, message, and hidden truth ever recorded. For centuries, these secrets have been safe, locked away behind intricate, almost unbreakable locks. Now picture a new kind of key, shimmering and ethereal, called the “Quantum Key.” Unlike ordinary keys, this…

House appropriators have reservations — or worse — about proposed CISA cuts

House appropriators on Tuesday challenged proposed budget cuts for the Cybersecurity and Infrastructure Security Agency, with Democrats saying the Trump administration was disturbingly moving money away from the agency and a key Republican saying he needed to see justifications for the reductions. The Trump administration has proposed cutting CISA funding by $491 million, and some…

Anthropic suggests tweaks to proposed U.S. AI chip export controls

Anthropic agrees with the U.S. government that implementing robust export controls on domestic-made AI chips will help the U.S. compete in the AI race against China. But the company is suggesting a few tweaks to the proposed restrictions. Anthropic released a blog post on Wednesday stating that the company “strongly supports” the U.S. Department of…

Cybercriminals intensify hunt for exposed Git secrets

Git configuration files exposed in public repositories are being aggressively dug up and looked into by threat actors to reveal sensitive secrets and authentication tokens unintentionally left behind in Git projects. A GreyNoise observation recorded a significant spike in search attempts for exposed Git configuration files between April 20 and April 21. “While the crawling…

Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool

A China-aligned advanced persistent threat (APT) group called TheWizards has been linked to a lateral movement tool called Spellbinder that can facilitate adversary-in-the-middle (AitM) attacks. “Spellbinder enables adversary-in-the-middle (AitM) attacks, through IPv6 stateless address autoconfiguration (SLAAC) spoofing, to move laterally in the compromised network, intercepting packets and

U.S. Companies Honed Their Surveillance Tech in Israel. Now It’s Coming Home.

Illustration: The Intercept In partnership with Rita Murad, a 21-year-old Palestinian citizen of Israel and student at the Technion Israel Institute of Technology, was arrested by Israeli authorities in November 2023 after sharing three Instagram stories on the morning of October 7. The images included a picture of a bulldozer breaking through the border fence in Gaza…

RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed Control

Cybersecurity researchers have revealed that RansomHub’s online infrastructure has “inexplicably” gone offline as of April 1, 2025, prompting concerns among affiliates of the ransomware-as-a-service (RaaS) operation. Singaporean cybersecurity company Group-IB said that this may have caused affiliates to migrate to Qilin, given that “disclosures on its DLS [data leak site] have doubled since

DHS Secretary Noem: CISA needs to get back to ‘core mission’

SAN FRANCISCO — Homeland Security Secretary Kristi Noem outlined her plans Tuesday to refocus the Cybersecurity and Infrastructure Security Agency (CISA) on protecting critical infrastructure from increasingly sophisticated threats — particularly from China — while distancing the agency from what she characterized as mission drift under previous leadership. Speaking at the 2025 RSAC Conference, Noem…

SentinelOne Uncovers Chinese Espionage Campaign Targeting Its Infrastructure and Clients

Cybersecurity company SentinelOne has revealed that a China-nexus threat cluster dubbed PurpleHaze conducted reconnaissance attempts against its infrastructure and some of its high-value customers. “We first became aware of this threat cluster during a 2024 intrusion conducted against an organization previously providing hardware logistics services for SentinelOne employees,” security

House passes bill to study routers’ national security risks

A bill requiring the Department of Commerce to study national security issues posed by routers and modems controlled by U.S. adversaries passed the House on Monday, advancing legislation that lawmakers say is “crucial” to understanding the devices’ cybersecurity risks. The House has moved quickly on the Removing Our Unsecure Technologies to Ensure Reliability and Security…

To Catch A Thief | Rubrik

For this special live recording of To Catch a Thief at The New York Stock Exchange, host and former lead cybersecurity and digital espionage reporter for The New York Times, Nicole Perlroth sits down with those who have been directly targeted by, traced, or directly engaged China’s state-sponsored hackers, diplomatically, or in the cyber domain:…

Erodiert die Security-Reputation der USA?

Trump stiftet Verunsicherung – auch wenn’s um Cybersicherheit geht. Joshua Sukoff | shutterstock.com Nachdem US-Präsident Donald Trump nun auch Cybersicherheitsunternehmen per Executive Order für abweichende politische Positionen abstraft, befürchten nicht wenige Branchenexperten, dass US-Sicherheitsunternehmen künftig ähnlich in Verruf geraten könnten wie ihre russischen und chinesischen Konkurrenten. Die zentralen Fragen sind dabei: Können sich CISOs beziehungsweise…

AI can help defenders stop nation-state threat actors at machine speed

Last year, the escalating concerns about Chinese threat actors breaching U.S. organizations reached a crescendo as federal authorities issued increasingly urgent advisories about China’s “Typhoon” groups infiltrating U.S. networks, pressing organizations to take immediate action. The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) warned that these groups were engaged…

Outside experts pick up the slack on safety testing on OpenAI’s newest model release

GPT-4.1, the latest family of generative AI models from OpenAI, was released earlier this month with promised improvements around coding, instruction following and context. It’s also the first model released by the company since it announced changes to the way it tests and evaluates products for safety. Unlike its previous fine-tuned models, OpenAI did not…

Chinese APT Billbug deploys new malware toolset in attack on multiple sectors

Chinese cyberespionage group Billbug has revamped its attack toolkit with new malware payloads in a wide-reaching campaign targeting multiple organizations in Southeast Asia. The new tools, which include credential stealers, a reverse shell, and an updated backdoor, were observed in attacks that lasted from August to February. “Targets included a government ministry, an air traffic…

A Chinese AI video startup appears to be blocking politically sensitive images

A China-based startup, Sand AI, has released an openly licensed video-generating AI model that’s garnered praise from entrepreneurs like Microsoft Research Asia founding director Kai-Fu Lee. But Sand AI appears to be censoring images that might raise the ire of Chinese regulators from the hosted version of the model, according to TechCrunch’s testing. Earlier this…

Rebuilding Maritime Cybersecurity Resilience: Charting an America First Course to Secure the U.S. Homeland

U.S. ports are vital to the flow of imports and exports; however, the entire maritime transportation system’s cybersecurity is exceedingly vulnerable. The August 2024 ransomware attack at the Port of Seattle resulted in significant cargo delays and a data breach of 90,000 individuals. Such a wide-scale incursion could have resulted in a longer loss of…

Lotus Panda Hacks SE Asian Governments With Browser Stealers and Sideloaded Malware

The China-linked cyber espionage group tracked as Lotus Panda has been attributed to a campaign that compromised multiple organizations in an unnamed Southeast Asian country between August 2024 and February 2025. “Targets included a government ministry, an air traffic control organization, a telecoms operator, and a construction company,” the Symantec Threat Hunter Team said in…

Will politicization of security clearances make US cybersecurity firms radioactive?

With the US government now tying security clearances to the support of specific political positions, many in the security community fear it may tar US vendors with the same brush as their Russian and Chinese counterparts. Will enterprise CISOs now have to worry about whether they can rely on American threat intel? More broadly, will…

Chinese shopping app Taobao joins DHgate in Top 5 on US App Store

The Chinese e-commerce marketplace app DHgate, which is now the No. 2 free iPhone app in the U.S., isn’t the only one that’s oddly benefiting from President Trump’s tariffs on U.S. imports from China. Another Chinese shopping app, Taobao, has now also entered the Top 5 as of Thursday. U.S. consumers began flocking to these…

Automakers selling cars in China banned from using ‘autonomous driving’ in ads

China is cracking down on how automakers advertise driver assistance features, banning terms like “autonomous driving,” “self-driving,” and “smart driving,” Reuters reported, citing a transcript of a meeting between the government and industry representatives. The updated rule will also prohibit automakers from rolling out improvements via software updates to advanced driving assistance systems in vehicles…

House investigation into DeepSeek teases out funding, security realities around Chinese AI tool

A House panel has concluded that the U.S. government should double down on export controls and other tools to slow down the progress of Chinese AI companies like DeepSeek, while also preparing for a future where those efforts fail. In a report released Wednesday, the House Select Committee on the Chinese Communist Party further fleshes…

Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates

The China-linked threat actor known as Mustang Panda has been attributed to a cyber attack targeting an unspecified organization in Myanmar with previously unreported tooling, highlighting continued effort by the threat actors to increase the sophistication and effectiveness of their malware. This includes updated versions of a known backdoor called TONESHELL, as well as a…

Shein and Temu to raise prices for US shoppers in response to tariffs

Temu and Shein plan to raise prices for U.S. customers starting next week on April 25th, due to President Donald Trump’s tariffs on goods shipped from China, the Associated Press reports. The 145% tariff on products made in China, along with Trump’s decision to end a customs exemption that had allowed goods under $800 to…

35 countries use Chinese networks for transporting mobile user traffic, posing cyber risks

U.S. allies are among the 35 countries where mobile providers employ China-based networks for transporting user traffic, opening travelers and residents in those nations to potential surveillance, an analysis published Thursday concludes. “Everyone knows that they have to be careful with their phones when they travel to China,” Rocky Cole, chief operating officer at iVerify,…

Trump administration reportedly considers a US DeepSeek ban

The Trump administration is considering new restrictions on the Chinese AI lab DeepSeek that would limit it from buying Nvidia’s AI chips, and potentially bar Americans from accessing its AI services, The New York Times reported on Wednesday. The restrictions are part of the Trump administration’s effort to compete with China on AI. Months after…

Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1

IntroductionThe Zscaler ThreatLabz team discovered new activity associated with Mustang Panda, originating from two machines from a targeted organization in Myanmar. This research led to the discovery of new ToneShell variants and several previously undocumented tools. Mustang Panda, a China-sponsored espionage group, traditionally targets government-related entities, military entities, minority groups, and non-governmental organizations (NGOs) primarily…

AMD estimates $800M charge on US license requirement for AI chips

AMD says that the U.S. government’s license control requirement for exporting AI chips to China and certain other countries may impact its earnings materially. If AMD doesn’t successfully obtain a license, the company could be on the hook for roughly $800 million in inventory, purchase commitments, and related reserves charges, the company said in a…

Exclusive: Peters, Rounds tee up bill to renew expiring cyber threat information sharing law

A bipartisan pair of senators are kicking off the race Wednesday to reauthorize a 2015 cyber threat information sharing law, a move that industry groups and cyber experts are eager to see happen before it’s set to expire in September. Advocates say the 10-year-old Cybersecurity Information Sharing Act has been vital to sharing threat information…

Überwachungssoftware infiziert gezielt Smartphones

Fingierte Messenger-Apps täuschen ihre Opfer und führen so freiwillig zur Installation der Schadsoftware. siro46 – shutterstock.com as Bundesamt für Verfassungsschutz und das britische National Cyber Security Centre warnen vor der Gefahr, die von den Schadprogrammen “Moonshine” und “BadBazaar” ausgeht. Dabei handelt es sich um zwei Varianten von Überwachungssoftware, die gezielt Smartphones infizieren, um sensible Daten zu sammeln.…

US government imposes license requirement on Nvidia H20 exports

Semiconductor giant Nvidia is facing unexpected new U.S. export controls on its H20 chips. In a filing Tuesday, Nvidia said it was informed by the U.S. government that it will need a license to export its H20 AI chips to China. This license will be required indefinitely, according to the filing — the U.S. government…

Nvidia H20 chip exports hit with license requirement by US government

Semiconductor giant Nvidia is facing unexpected new U.S. export controls on its H20 chips. In a filing Tuesday, Nvidia said it was informed by the U.S. government that it will need a license to export its H20 AI chips to China. This license will be required indefinitely, according to the filing — the U.S. government…

Chinese law enforcement places NSA operatives on wanted list over alleged cyberattacks

China stepped up its allegations of U.S. cyberattacks Tuesday, with local law enforcement saying they were investigating three National Security Agency operatives they had placed on a wanted list and a national official condemning the alleged attacks. State media outlet Xinhau advanced the claims in two stories, one detailing a hacking campaign during the Asian…

The AI Fix #46: AI can read minds now, and is your co-host a clone?

In episode 46 of The AI Fix, China trolls US tariffs, a microscopic pogoing flea-bot makes a tiny leap forward for robotics, Google unveils the Agent2Agent protocol, a robot dog is so cute it ruins Graham’s entire day, and Europe commits €20 billion and all of its buzzwords to five moonshot AI gigafactories. Graham brings…

China alleges US cyber espionage during the Asian Winter Games, names 3 NSA agents

China has accused the US of conducting more than 170,000 cyberattacks against the Asian Winter Games held in Harbin this February. Officials have named three alleged NSA operatives they claim spearheaded the digital assault. The Harbin Public Security Bureau identified Katheryn A. Wilson, Robert J. Snelling, and Stephen W. Johnson as NSA personnel responsible for…

Trump Revenge Tour Targets Cyber Leaders, Elections

President Trump last week revoked security clearances for Chris Krebs, the former director of the Cybersecurity and Infrastructure Security Agency (CISA) who was fired by Trump after declaring the 2020 election the most secure in U.S. history. The White House memo, which also suspended clearances for other security professionals at Krebs’s employer SentinelOne, comes as…

38 consumer startup founders lobby over Trump tariffs: One faces a surprise $200K bill

Small businesses could be crushed under President Trump’s increased tariffs, according to an open letter by 38 female consumer product founders. While Trump paused his tariff increases for 90 days for various countries – setting the rate at 10% for now  –  China’s was raised to 145%, which includes the previous 20% levy. In the…

China-based SMS Phishing Triad Pivots to Banks

China-based purveyors of SMS phishing kits are enjoying remarkable success converting phished payment card data into mobile wallets from Apple and Google. Until recently, the so-called “Smishing Triad” mainly impersonated toll road operators and shipping companies. But experts say these groups are now directly targeting customers of international financial institutions, while dramatically expanding their cybercrime…

Nvidia’s H20 AI chips may be spared from export controls — for now

Nvidia CEO Jensen Huang appears to have struck a deal with the Trump administration to avoid export restrictions on the company’s H20 AI chips. The H20, the most advanced Nvidia-produced AI chip that can still be exported from the U.S. to China, was reportedly spared thanks to a promise from Huang to invest in new…

Treasury bureau notifies Congress that email hack was a ‘major’ cybersecurity incident

The Office of the Comptroller of the Currency has notified Congress that a February breach of its email system is classified as a major cybersecurity incident. The incident was first disclosed Feb. 26, though the OCC provided virtually no details at the time, only saying that it had resolved a security incident “involving an administrative…

Bill to study national security risks in routers passes House committee

A federal study into the national security risks posed by routers, modems and similar devices controlled by U.S. adversaries moved one step closer to law Tuesday by advancing out of the House Energy and Commerce Committee. The Removing Our Unsecure Technologies to Ensure Reliability and Security (ROUTERS) Act from Reps. Bob Latta, R-Ohio, and Robin…

Tech experts recommend full steam ahead on US export controls for AI

Technology experts pressed Congress to maintain export controls on semiconductor chips and other technologies, telling lawmakers Tuesday that the restrictions are among the most effective strategies to slow China and other rival countries in the AI race, thereby helping U.S. companies hold a competitive edge. Placing export controls on these technologies is not new: both…

Apple might import more iPhones from India to side-step China tariffs

Apple is considering importing more iPhones from India to side-step the 54% additional tariffs on goods imported from China that U.S. President Donald Trump announced last week, the Wall Street Journal reported, citing anonymous sources. The company sees this as a short-term measure while it seeks to negotiate with the Trump administration to get an…

Apple might import more iPhones from India to side-step China tariffs

Apple is considering importing more iPhones from India to side-step the 54% additional tariffs on goods imported from China that U.S. President Donald Trump announced last week, the Wall Street Journal reported, citing anonymous sources. The company sees this as a short-term measure while it seeks to negotiate with the Trump administration to get an…

Analyst says Apple, Tesla have biggest exposure to Trump’s tariffs

Wedbush Securities analyst Dan Ives slashed his price targets for Apple and Tesla over the weekend as President Trump’s tariffs threaten to disrupt both businesses.  “The tariff economic Armageddon unleashed by Trump is a complete disaster for Apple given its massive China production exposure,” Ives said in a warning note over the weekend. “In our…

DMARC Adoption among APAC’s Higher Education Sector

On the heels of our DMARC adoption research in Europe’s higher education sector, we’re taking a look to see how schools in the Asia Pacific region are faring with their email security. The post DMARC Adoption among APAC’s Higher Education Sector appeared first on Security Boulevard.

China-Linked Earth Alux Uses VARGEIT and COBEACON in Multi-Stage Cyber Intrusions

Cybersecurity researchers have shed light on a new China-linked threat actor called Earth Alux that has targeted various key sectors such as government, technology, logistics, manufacturing, telecommunications, IT services, and retail in the Asia-Pacific (APAC) and Latin American (LATAM) regions. “The first sighting of its activity was in the second quarter of 2023; back then,…

After fake employees, fake enterprises are next hiring threat to corporate data

Chinese companies are trying to cut Taiwan’s lead in semiconductor technology by hiring away its best engineering talent through ‘front’ companies that hide their connections to China, the Taiwanese Ministry of Justice Investigation Bureau (MJIB) has alleged. In a dramatic crackdown on the practice last week, MJIB said its agents raided 11 Chinese companies in…