The FBI has dismantled proxy tools used by Chinese hackers in a widespread campaign against NASA, the Federal Reserve, the US Senate, and the Justice Department. The operation marks a significant coordinated response to months of intrusions into critical US infrastructure.
The Department of Justice announced the disruption of hacking tools deployed by Chinese state-sponsored actors who conducted a mass campaign against multiple US government agencies and infrastructure operators.
Targets included NASA, the Federal Reserve, the US Senate, and the Justice Department itself, according to DOJ officials. The campaign represented one of the most extensive intrusions into US government systems in recent years.
The FBI's disruption effort focused on dismantling proxy infrastructure used to mask the attackers' identity and origin. By targeting these intermediate systems, federal investigators cut off the operational capability of the hacking campaign.
The Chinese hacking effort relied on compromising internet-facing devices and services to establish persistent access into victim networks. Investigators traced the tools and techniques back to Chinese state-sponsored threat actors, though specific attribution details remain limited in public statements.
The operation demonstrates increased coordination between US law enforcement and intelligence agencies in countering persistent cyber threats. Similar disruption campaigns have targeted Russian and Iranian hacking infrastructure in previous years.
US officials have not disclosed the full scope of data accessed or systems compromised during the campaign. Affected agencies have begun notifying relevant parties and implementing security remediation measures.
The disruption does not eliminate the underlying threat from Chinese cyber operations. Security researchers expect continued attempts to penetrate US government systems and critical infrastructure through alternative methods and tools.
The FBI's action underscores ongoing tensions between the US and China over cyber espionage operations targeting government and private sector networks. Chinese officials have previously denied involvement in state-sponsored hacking campaigns.
A new Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation.
Snowflake is phasing out password authentication for legacy service accounts, requiring organizations to adopt passwordless methods. The real challenge: identifying which accounts exist, who manages them, and what access they hold.
Medical technology company Boston Scientific disclosed a cyberattack that disrupted IT systems and operations worldwide. The company is working to restore normal services.
The FBI has disrupted infrastructure used by Chinese state-sponsored actors to conduct cyber espionage operations. The takedown targeted a technical quartermaster operation that provided reconnaissance, proxy management, and operational routing capabilities.