China-linked hackers breach Pakistani police databases to harvest biometric and citizen records

Even close partners are not exempt from Chinese espionage. State-linked operators penetrated municipal police networks across Pakistan, siphoning biometric databases, criminal files, and hotel registries from headquarters in Balochistan and Islamabad, SecurityWeek reported from a SentinelLabs investigation. The multi-year breach gave Chinese intelligence direct, unmonitored visibility into local police patrols and civilian movements along the China-Pakistan Economic Corridor (CPEC).

The operation exposes the reality of sovereign infiltration of allies, accompanied by Beijing’s drive for biometric panopticon export. While diplomats in Beijing and Islamabad publicize their “ironclad friendship,” Chinese security services routinely bypass formal intelligence-sharing channels. They hacked their partner’s police servers to run unilateral digital surveillance, treating Pakistani law enforcement data as raw material to protect Chinese construction investments.

Exporting this dragnet strips foreign citizens of any expectation of privacy. Ordinary Pakistani nationals are now cataloged inside Chinese state intelligence databases without their knowledge or consent. Beijing has made it clear that allied sovereignty ends whenever the party’s overseas security interests begin.

Chinese rare earth suppliers cut US shipments under state pressure and supply-chain sanctions

Beijing is turning the mineral valve shut again. Chinese state-owned rare earth processors abruptly halted shipments of specialized magnetic alloys and refined minerals to American manufacturers, Reuters reported. The freeze followed Ministry of Commerce retaliatory measures against international auditing firms. Controlling over ninety percent of global permanent magnet refining, Chinese authorities pressured domestic suppliers to freeze export contracts, choking supplies vital for defense avionics, electric vehicle motors, and semiconductor tools.

The embargo is a clear act of economic coercion through critical mineral extortion. It pulls directly from Beijing’s 2010 playbook against Japan during the Senkaku maritime standoff, as well as its recent export limits on gallium and antimony. Whenever a geopolitical dispute heats up, the party weaponizes its refining monopoly to force commercial concessions, tearing up private contracts to punish foreign buyers.

The freeze also represents the formal criminalization of due diligence. By targeting audit groups like the Responsible Business Alliance and cutting off shipments over supply-chain audits, the party demands total opacity. Global manufacturers face an ugly choice: ignore forced labor risks in Chinese supply chains, or lose access to essential industrial raw materials entirely.

China-linked 'Fire Ant' hackers compromise core Cisco routers to blind security telemetry

Chinese state hackers are gutting network visibility from the inside out. A state-sponsored group tracked as Fire Ant hijacked core Cisco IOS XR edge routers and central authentication servers across critical utility backbones, incident response firm Sygnia reported via BleepingComputer. The operators established stealth GRE routing tunnels to harvest administrative credentials. Once inside, they modified command binaries directly on the hardware to ensure audit log suppression, leaving security teams completely blind as intruders moved deeper into the perimeter.

The campaign relies on edge device exploitation, following the blueprint perfected by Beijing’s Volt Typhoon and Salt Typhoon units. Edge routers and telecommunications gateways rarely support third-party endpoint security software. Fire Ant took advantage of that blind spot. By killing audit logging at the firmware level, the hackers eliminated the telemetry needed for forensic detection, turning trusted corporate hardware into silent listening posts.

The danger lies in the depth of this critical infrastructure infiltration. Hitting identity servers and core transit routers gives Chinese intelligence persistent footholds inside civilian water, power, and transport networks. Those access points are not designed for routine intelligence collection. They are pre-positioned assets built to knock foreign municipal systems offline during a crisis.

Beijing amends defense mobilization law to conscript AI and commercial drones for wartime use

China is putting its private technology sector on a wartime footing. Under sweeping revisions to the National Defense Mobilization Law passed by the National People’s Congress Standing Committee, the Central Military Commission can now requisition commercial artificial intelligence models, private drone fleets, and cloud clusters at will, the South China Morning Post reported. Taking effect October 1, the statutory mandate legally compels domestic software developers and robotics firms to hand over proprietary algorithms and hardware the moment the party declares a security crisis.

The law represents an aggressive escalation of civil-military fusion through authoritarian legalism. It builds on Article 7 of the 2017 National Intelligence Law, which ordered all citizens to assist state intelligence agencies. Through this statutory lawfare, the party formally codifies the eradication of corporate autonomy. Private tech founders have no legal shield and no independent court to appeal to when military officers demand their server keys. Every commercial app and drone startup in China is now an auxiliary unit of the PLA.

The overhaul serves a dual purpose: preparing for conflict over Taiwan and signaling total societal mobilization to neighboring democracies. Domestic technological breakthroughs are not meant to foster civilian prosperity. Instead, the party-state legally annexes private innovation to feed its military apparatus, turning ordinary economic growth into a tool of geopolitical coercion.

PRC state-backed 'QTFY' hacking ring burrows into US federal agencies and critical infrastructure

China’s civilian front companies are back in the dock. According to unsealed Department of Justice indictments reported by CyberScoop, contract hackers operating under a Nanjing-based tech firm called Xinjiuwei breached NASA flight research centers, the U.S. Treasury, and major commercial banking networks. The contractor operated as an operational arm of the Ministry of State Security. Under the codename QTFY, operators tunneled through enterprise VPN appliances, deployed custom webshells, and spent months siphoning telemetry on space propulsion and aerospace blueprints.

The operation is a textbook use of commercial front cutouts for pretextual cloaking. Beijing has run this play for years, mirroring previous DOJ indictments against Hainan Xiandun and Chengdu-based shells. Setting up commercial front companies gives state intelligence a layer of plausible deniability. The Ministry of State Security directs the intrusions from behind a corporate facade, protecting central party leadership from diplomatic fallout whenever an operation blows up.

The target list reveals the real objective: critical infrastructure pre-positioning. Intruders skipped routine embassy correspondence to dig deep into financial settlement engines and civilian space architectures. Those footholds give Beijing disruptive leverage long before a shot is fired. When state operators burrow into foreign public utilities, peacetime espionage quietly transforms into wartime sabotage.