The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWeek.

The United States government has reportedly disrupted a Chinese hacking platform that was allegedly used to target military and critical infrastructure entities. The operation specifically focused on a group identified as QTFY, which is described as providing hacking services to the Chinese government and other clients. The disruption aims to dismantle an infrastructure enabling state-sponsored cyber espionage and potential sabotage.
QTFY is characterized as a provider of hacking services, suggesting it operates as a sophisticated cyber mercenary group or a state-affiliated entity with a service-oriented model. This type of organization typically develops or acquires a suite of tools and exploits, offering them to clients for specific objectives. The "platform" aspect implies a centralized infrastructure for command and control, data exfiltration, and potentially the distribution of malware or access to compromised systems. Disrupting such a platform often involves legal actions, technical takedowns of servers, seizure of domains, and potentially the arrest or sanctioning of individuals associated with the group.
The targeting of military and critical infrastructure sectors indicates a focus on high-value strategic objectives. Attacks on military networks typically aim for intelligence gathering, intellectual property theft related to defense technologies, or disruption of operations. Critical infrastructure, encompassing sectors like energy, water, telecommunications, and finance, represents targets whose compromise could lead to widespread societal disruption, economic damage, or even loss of life. The methods employed by groups like QTFY could range from sophisticated spear-phishing campaigns and supply chain attacks to exploiting known vulnerabilities in widely used software or hardware.
Mitigation strategies against such sophisticated threats generally involve a multi-layered approach. Organizations, particularly those in critical infrastructure and defense, are advised to implement robust network segmentation, multi-factor authentication, and continuous monitoring for anomalous activity. Regular patching and vulnerability management are crucial, as is employee training on cybersecurity best practices to counter social engineering tactics. Furthermore, threat intelligence sharing among government agencies and private sector entities can help in identifying and defending against emerging threats from groups like QTFY.
The reported disruption highlights an ongoing trend of nation-state actors leveraging advanced persistent threats (APTs) to achieve strategic objectives. While the specific mechanisms of the disruption were not detailed, such operations often involve international cooperation and intelligence sharing. This action underscores the commitment of the U.S. government to counter cyber threats originating from state-sponsored groups, particularly those targeting vital national security and economic interests.
The focus on a group like QTFY also brings attention to the evolving landscape of cyber warfare, where state actors may outsource or utilize third-party groups for deniability or to scale their operations. This model complicates attribution and defense, as the lines between state-sponsored activity and criminal enterprise can become blurred. The disruption serves as a reminder of the persistent and evolving nature of cyber threats and the continuous efforts required to secure digital ecosystems.
Ultimately, this disruption represents a significant step in countering a specific vector of cyber espionage and potential sabotage. It reinforces the importance of proactive measures by both government and private sector organizations to protect against sophisticated cyber adversaries. The incident also underscores the global nature of cyber threats and the necessity for coordinated international responses to safeguard critical digital assets.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a