Beijing’s not saying why, which is just what happened when it investigated Micron

China's Cyberspace Administration (CAC) has initiated a security review of products from Palo Alto Networks, a major cybersecurity vendor. The CAC's public statement on the matter indicated the review is necessary "to ensure the safe and stable operation of critical information infrastructure, prevent cybersecurity risks and vulnerabilities, and safeguard national security." No further details regarding the specific reasons for the probe have been disclosed by Beijing.
Palo Alto Networks has confirmed the review, stating that it maintains "the highest standards of business conduct and security practices and ethics across our global operations." The company added that, at present, there is "no impact to our ability to support customers or deliver our products and services in the region."
This action by the Chinese regulator bears similarities to a 2023 investigation into products from the memory manufacturer Micron. In that instance, the CAC also announced a security probe without providing detailed explanations. Although Micron had previously been involved in intellectual property and antitrust disputes in China, neither the company nor Chinese authorities explicitly linked those issues to the security investigation.
Weeks after announcing the Micron probe, the CAC concluded that Micron's products posed an unacceptable security risk for critical infrastructure operators, effectively banning their sale to such entities. Micron subsequently ceased selling its datacenter and server products in China, a decision that resulted in billions of dollars in lost annual revenue for the company. This move also created opportunities for domestic Chinese memory manufacturers, who face restrictions on selling to American companies.
Palo Alto Networks has not publicly disclosed its revenue figures specifically from China, making it difficult to estimate the potential financial impact of any adverse findings from the current review. China is home to several cybersecurity companies, including Huawei and H3C, whose product offerings overlap with those of Palo Alto Networks.
For years, China has accused Western technology companies of complicity in US surveillance and offensive cyber operations. Conversely, Western governments have leveled similar accusations against Chinese tech firms like Huawei and ZTE. The previous ban on Micron products in China did not significantly affect the company's reputation outside the country, with the recent AI boom contributing to substantial financial gains for Micron.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed