Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Affecting China

View all threats affecting or targeting China. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Country:ChinaChina

Threats Affecting China

Click on any threat for detailed analysis and mitigation recommendations

How fake signups drive AI fraud
0

A thriving gray market has emerged offering discounted access to AI models through fraudulent account registrations that exploit free trials and startup credits. Services like Poison Claude and Ecomagent offer 70-90% discounts by creating fake accounts on platforms such as AWS Bedrock and Google Cloud, then reselling access through custom API endpoints. The demand is driven by cost considerations, access restrictions in regions like China, and desire for anonymity. Fraudulent registration campaigns targeting AI video services show over 105,000 brute-force signup attempts using bots, VPNs, and disposable email domains. The operations leverage residential proxies to evade detection and accept cryptocurrency payments. These services operate through sophisticated AI gateways and are advertised on underground forums and messaging platforms, particularly in Chinese-language markets, representing a significant platform abuse challenge for AI service providers.

Join the discussion
ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution VulnerabilityCVE-2026-15679
0

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15679.

Join the discussion
ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityCVE-2026-18303
0

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303.

Join the discussion
ZDI-26-462: GIMP APNG File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18309
0

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18309.

Join the discussion
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
0

Flying Eagle is an Android remote access tool (RAT) whose source code was leaked in early 2026, leading to a fractured criminal ecosystem with about 170 active servers. The malware is distributed via Telegram channels offering modified versions and operational support, targeting Chinese users primarily with phishing overlays aimed at financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, enhancing credential theft capabilities for Chinese banking apps, cryptocurrency wallets, and social media. The threat leverages social engineering and impersonation tactics, including malicious APKs mimicking official Chinese government apps. While primarily focused on China, the platform's templates suggest potential for broader international targeting.

Join the discussion
Unpatched Fastjson Vulnerability Exploited in Attacks
0

The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek .

Join the discussion
Hackers target US firms in FastJson RCE zero-day attacks
0

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]

Join the discussion
PTC Windchill Vulnerability Exploited in Ransomware Campaign
0

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek .

Join the discussion
Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
0

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches Background On July 21, Oracle released its Critical Patch Update (CPU) for July 2026 , the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this quarter, 18% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 52.7%, followed by medium severity patches at 24.7%. This quarter's update includes 261 critical patches across 228 CVEs. Severity Issues Patched CVEs Critical 261 228 High 763 613 Medium 358 332 Low 67 62 Total 1449 1235 Analysis This quarter, the Oracle E-Business Suite product family contained the highest number of patches at 410, accounting for 28.3% of the total patches, followed by Oracle Fusion Middleware at 355 patches, which accounted for 24.5% of the total patches. A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication. Oracle Product Family Number of Patches Remote Exploit without Auth Oracle E-Business Suite 410 45 Oracle Fusion Middleware 355 219 Oracle Communications 168 122 Oracle PeopleSoft 84 45 Oracle MySQL 54 9 Oracle Siebel CRM 45 32 Oracle Commerce 39 26 Oracle Supply Chain 39 16 Oracle Financial Services Applications 31 26 Oracle GoldenGate 27 9 Oracle Enterprise Manager 27 13 Oracle Retail Applications 22 20 Oracle JD Edwards 20 4 Oracle Java SE 19 17 Oracle Virtualization 16 0 Oracle Database Server 15 6 Oracle TimesTen In-Memory Database 14 4 Oracle Utilities Applications 14 10 Oracle Construction and Engineering 7 7 Oracle Analytics 7 5 Oracle Systems 6 0 Oracle SQL Developer 5 5 Oracle Autonomous Health Framework 4 3 Oracle Application Testing Suite 4 4 Oracle Food and Beverage Applications 4 4 Oracle HealthCare Applications 4 4 Oracle APEX 3 2 Oracle Hospitality Applications 2 2 Oracle Essbase 1 1 Oracle Global Lifecycle Management 1 1 Oracle NoSQL Database 1 1 Oracle Spatial Studio 1 1 Solution Customers are advised to apply all relevant patches in this quarter's CPU. Please refer to the July 2026 advisory for full details. Identifying affected systems A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released. Get more information Oracle Critical Patch Update Advisory - July 2026 Oracle July 2026 Critical Patch Update Risk Matrices Oracle Advisory to CVE Map Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats. Learn more about Tenable One , the Exposure Management Platform for the modern attack surface.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Country: China
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses