LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
security

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

MI5 has issued a warning regarding a Chinese state security service operation that reportedly involved over 100 academics linked to the U.K. The U.K.'s domestic intelligence and security agency stated that these individuals have inadvertently or wittingly contributed to China's intelligence gathering efforts. The alert, issued on September 30, 2026, specifically named the China General…

ZeroDay News ·

Source: The Hacker News

Photo: Txllxt TxllxT (CC BY-SA 4.0) via Wikimedia Commons

MI5 has issued a warning regarding a Chinese state security service operation that reportedly involved over 100 academics linked to the U.K. The U.K.'s domestic intelligence and security agency stated that these individuals have inadvertently or wittingly contributed to China's intelligence gathering efforts. The alert, issued on September 30, 2026, specifically named the China General Technology Research Institute (CGTRI) as a key entity in this operation.

According to the MI5 "Security Service Espionage Alert," the primary purpose of the CGTRI, also known as 中国通用技术研究院, is to fund research. This funding mechanism is reportedly being utilized by Beijing's state security service to advance its intelligence objectives. While the alert does not detail the specific nature of the research or the intelligence sought, such operations typically focus on dual-use technologies, critical infrastructure vulnerabilities, or strategic economic information.

The involvement of academics in such schemes often occurs through legitimate-seeming research collaborations, grants, or conferences. Foreign intelligence services commonly leverage the open nature of academic research and international scientific exchange to gain access to sensitive information, intellectual property, and expertise. Academics may be unaware that their research is being co-opted for intelligence purposes, believing they are engaged in standard scientific cooperation.

The scope of this particular operation, involving more than 100 U.K.-linked academics, suggests a broad and sustained effort. Intelligence agencies frequently cast a wide net, seeking to identify individuals with access to valuable information or specialized knowledge. The targeting of academics is a common tactic, as universities are often hubs of cutting-edge research and development, including areas with significant national security implications.

Mitigation for such risks typically involves increased awareness campaigns within academic institutions, enhanced due diligence for international research partnerships, and clear guidelines on intellectual property protection. Universities are often advised to implement robust vetting processes for foreign funding and collaborations, particularly when dealing with entities linked to state-sponsored organizations. Researchers are also encouraged to report any suspicious overtures or unusual requests for information.

This incident underscores the persistent challenge posed by state-sponsored intelligence operations targeting academic and research sectors. Such activities highlight the ongoing efforts by foreign powers to acquire strategic advantages through non-traditional means, leveraging the globalized nature of scientific inquiry. The MI5 alert serves as a reminder to the academic community and government agencies alike about the need for vigilance against sophisticated intelligence gathering tactics.

ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.