LIVE · cybersecurity feed
Live wire
security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

zeroday.news ·

A Chinese state-sponsored hacking group known as Volt Typhoon has spent the last three years embedding malware into critical infrastructure across the United States, positioning itself to disrupt essential services. This activity, described by some as "digital bombs" strapped to infrastructure, has prompted concerns about potential widespread societal chaos.

Initially, Volt Typhoon was believed to be targeting electric grids and telecommunication networks in the continental U.S. and Guam, likely with a focus on U.S. military facilities and surrounding infrastructure. The prevailing theory suggested these actions were in preparation for a potential Chinese invasion of Taiwan, aiming to delay a U.S. response.

However, subsequent analysis revealed that the group's activities extended beyond military targets to include civilian critical infrastructure, such as electric and water utilities, across the entire U.S. This includes smaller towns like Littleton, Massachusetts, raising questions about the broader motivations behind these intrusions. Experts now theorize that China might be seeking the capability to cause significant disruption and distraction within the U.S. during a potential crisis, such as a Taiwan invasion.

While Volt Typhoon has not yet initiated any disruptive cyberattacks, the groundwork laid by the group has spurred simulations and war games to assess potential responses. One such closed-door exercise, attended by approximately 30 insurance executives in Times Square, simulated a scenario where a Chinese cyberattack simultaneously disabled 5,000 U.S. water utilities.

The war game, designed by a former strategist for the Cybersecurity and Infrastructure Security Agency (CISA), aimed to test reactions under a countdown clock. The simulated outcomes included burst water mains, hospital evacuations, and insulin shortages, highlighting the potential for severe societal impact.

The involvement of insurance executives in such a simulation underscores their critical, if often overlooked, role in national cybersecurity response. When organizations experience a cyberattack, their first call is frequently to their insurance provider. These providers then facilitate access to pre-approved lawyers and cybersecurity incident responders, effectively controlling the initial stages of a national response due to their financial backing of recovery efforts.

The persistent and widespread nature of Volt Typhoon's intrusions into U.S. civilian infrastructure represents a significant concern for cybersecurity experts and government officials. The group's apparent restraint in activating these "digital bombs" has, paradoxically, allowed their activities to remain somewhat under the radar, despite the severe potential consequences should they decide to launch a disruptive attack.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

security

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.

malwarehigh

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]