LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
security

EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank

The Royal United Services Institute (RUSI), a UK-based think tank, has issued a report highlighting that the European Union's current approach to technology procurement leaves member states vulnerable to risks associated with Chinese vendors. RUSI advocates for a new, comprehensive risk assessment framework applicable across all EU members to strengthen the bloc's collective security without…

ZeroDay News ·

Source: The Register — Security

The Royal United Services Institute (RUSI), a UK-based think tank, has issued a report highlighting that the European Union's current approach to technology procurement leaves member states vulnerable to risks associated with Chinese vendors. RUSI advocates for a new, comprehensive risk assessment framework applicable across all EU members to strengthen the bloc's collective security without infringing on national security policies.

Currently, the EU's primary mechanism for addressing 5G security, the EU Toolbox for 5G Security, remains voluntary. Since its introduction in January 2020, only 10 of 27 member states have fully implemented it. To address this, the European Commission (EC) proposed amendments to the Cyber Security Act (CSA) earlier this year. These amendments would empower the EC to compile a list of untrusted vendors, whose equipment would then be subject to a mandatory "rip and replace" policy within 36 months for 18 critical sectors. The EC has indicated that Huawei and ZTE would likely be among the first vendors suggested for this list if the amendments pass.

A key challenge, however, is the absence of an official definition or legal category for a "high-risk vendor," allowing individual countries to bypass scrutiny when procuring technology. RUSI's report illustrates this disparity by examining Germany, Spain, and the UK. Germany, with China as its largest trading partner (a relationship valued at €251.8 billion annually), has historically prioritized economic ties. In 2024, Chinese suppliers constituted an estimated 59 percent of Germany’s 5G RAN. While a shift is anticipated under Chancellor Friedrich Merz, RUSI does not foresee immediate significant changes.

Spain's 5G RAN saw an estimated 32 percent share from Chinese equipment in 2024, a figure expected to decrease. Spain's procurement decisions have often favored cost-effectiveness, and its government does not share the same level of national security concerns regarding China as the UK or US. A recent controversy involved Huawei securing a contract for storing judicial wiretap recordings. In contrast, the UK is on track to eliminate Chinese technology from its telecoms network by the end of next year, largely influenced by US concerns regarding Huawei.

RUSI confirms that concerns about Chinese IT vendors are "well-founded." The Chinese government possesses legal authority to compel companies like Huawei to provide data on demand, host Chinese Communist Party representatives, and report activities deemed a threat to national security. Furthermore, a Chinese law mandates that tech companies report vulnerabilities to the government within 48 hours of discovery, while prohibiting disclosure to overseas counterparts, except for the product vendor itself. RUSI states this effectively transforms China's private sector security research into a state-controlled pipeline, granting intelligence services early access to exploitable vulnerabilities.

Beyond technical security, China's technological advancements introduce economic risks. Chinese vendors often offer more capable products at lower prices than their EU or US counterparts, creating a global reliance that could lead to "unwelcome dependencies" or cement China's dominance in critical supply chains. China has previously demonstrated a willingness to leverage this influence, such as threatening Germany with "consequences" for economic ties during the 2019 5G debate.

However, RUSI questions the efficacy of the EC's proposed CSA amendments, arguing that blanket bans do not inherently address underlying security vulnerabilities. Even without Chinese vendors, products from "trusted" countries have demonstrated vulnerabilities, as evidenced by the 2024 Salt Typhoon attack on US telco networks.

RUSI also notes that a CSA-style designation system could potentially apply to US companies. Some European countries view US vendors as similarly risky, albeit for different reasons. Germany, for instance, expresses concerns about its relationship with the US, and similar dependencies on US technology could arise if relations sour. In Spain, where US cloud companies are dominant, anti-US sentiment exists, particularly regarding surveillance concerns. Some officials reportedly view US legal instruments like the Patriot Act as creating sovereignty risks comparable to China’s National Intelligence Law, a narrative RUSI describes as politically convenient but flawed upon legal examination.

To enact meaningful change, RUSI suggests the EU must cultivate "greater economic courage" and approach tech procurement as a means to secure critical infrastructure, rather than merely a compliance exercise.

ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Frontline Education Breach Impacts K-12 School District Staff

Frontline Education, a prominent software provider for K-12 school districts in the United States, has confirmed a data breach that exposed the personal information of school staff. The incident, which was discovered on August 14, 2026, stemmed from a vulnerability in a third-party software product utilized by the company.

vulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

ai

Apple tightens macOS disk access as AI agents become more powerful

Apple is implementing stricter controls for Full Disk Access in macOS, citing an increased risk to user privacy from increasingly capable and autonomous AI agents. The company indicated that future macOS versions will require users to take explicit steps to grant applications this permission. A specific rollout date and the precise mechanics of these new controls have not yet been detailed.

nation-state

doxx.net opens Agentic Defined Networking public beta, raises $38 million

doxx.net has launched the public beta of its Agentic Defined Networking (ADN) platform, which enables users and their AI agents to establish private, secure networks and communicate without intermediary servers. The company also announced it has secured $38 million in Series A funding, led by Andreessen Horowitz, with additional participation from Animo Ventures and Focal.vc. As part of the…

vulnerability

AI slop submissions force Google to freeze its open-source bug bounty

Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) for new product vulnerability submissions, effective October 1, 2026. The company cited a substantial increase in automated, AI-generated reports, most of which were invalid, as the reason for the pause. This influx of low-quality submissions overwhelmed the engineers and open-source maintainers…

nation-state

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

David Robinson, a veteran safety expert at OpenAI, has resigned from the company, citing concerns about its culture and rapid AI development model. Robinson, who was instrumental in authoring safety reports accompanying major product launches during his three-and-a-half-year tenure, stated that he believes the company's current trajectory is unacceptable.