The U.S. Congress's bipartisan Select Committee on China released a 49-page report, "Stranger Pings," detailing the threat posed by China-controlled infrastructure within the U.S. telecommunications backbone. The report suggests that Chinese telecom firms operating in the U.S. maintain trusted positions that could be abused by Chinese threat actors to preserve access and hide activity, potentially facilitating future cyber operations against the U.S.
The Committee noted that one Chinese telecommunication provider included an 'Acceptable Use' Policy in contracts with U.S. companies, prohibiting the broadcasting of political news or information violating PRC state security laws or social stability.
The threat actor known as SideWinder has adopted a new multi-stage attack chain. This chain abuses ClickOnce application files, which are delivered via phishing PDF documents, to deploy Rust-based backdoors. These implants establish persistence through registry modifications, collect host intelligence, and receive remote commands from external servers hosted on platforms like Cloudflare Workers.
An active malicious package campaign, dubbed "Flooding Dropper," has been disclosed, involving a large-scale operation with 846 software components. Sonatype reported that the attacker appears to automate parts of the npm account and package creation process, combining terms such as 'bigops' and 'bnpl' with other words and recurring version patterns. When installed, these packages download further malicious content.
The reported threats highlight a pattern of exploiting common vulnerabilities, including exposed servers, recycled bugs, poisoned agent instructions, and remote-access tools disguised as support software. These incidents underscore how ordinary systems can be compromised by trusting too much, too early, across various attack vectors.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
This week's security report highlights several active threats, including a U.S. Congressional committee report on China-linked telecom infrastructure risks, a new ClickOnce phishing chain used by SideWinder, and an npm supply chain attack involving 846 malicious packages. These incidents demonstrate ongoing vulnerabilities in telecommunications, software delivery, and supply chain security, posing risks to various organizations and users.