At #HagueTIX2026 @meidanowski.bsky.social and @euben.bsky.social are discussing how China scales cyber operations: www.thehagueprogram.nl/tix-speakers... www.thehagueprogram.nl/tix-speakers... @thehagueprogram.bsky.social @fggaleiden.bsky.social
Eugenio Benincasa
@euben.bsky.social
Cyber Defense Researcher @ethz.ch. Former Italian govt, Pacific Forum and NYPD. LUISS & Columbia University Alum.
We’re proud Synapse is playing a part in the hands-on workshop at @ccdcoe #CyCon2026 with @lawsecnet.counterintelligence.pl, @euben.bsky.social, and Jiro Minier: “Threat Actors Can Do Public-Private Partnership Too”
France hosts the EU’s densest cluster of cyber partnerships with Chinese defense-linked universities, raising exposure to dual-use knowledge transfer, EU funding access, and institutional influence. New Natto Thoughts’ piece from @euben.bsky.social www.nattothoughts.com/p/faux-amis-...
Faux Amis: How France Stands Apart in Europe’s High-Risk University Cyber Partnerships with China
France hosts the EU’s densest cluster of cyber partnerships with Chinese defense-linked universities, raising exposure to dual-use knowledge transfer, EU funding access, and institutional influence
nattothoughts.com
Europe is building stronger systems to report vulnerabilities, but it risks overlooking the people who discover the flaws first: independent security researchers, write @euben.bsky.social and Max van der Horst: bindinghook.com/europe-forge... #EUcybersecurity
Europe forgets its bug hunters at its own peril
Without safe harbour for independent vulnerability researchers, Europe risks discouraging the reporting its disclosure regime needs
bindinghook.com
The Tianfu Cup is back this year. See the analysis of the event by Eugenio @euben.bsky.social published today on Natto Thoughts. www.nattothoughts.com/p/the-tianfu...
The Tianfu Cup Returns Under MPS Leadership as AI Takes Center Stage
After a two-year hiatus, the Tianfu Cup returns under MPS lead, combining AI-assisted vulnerability discovery and exploitation, a new competition track, and less transparency in vulnerability handling
nattothoughts.com
We continue exploring provincial level’s involvement in cyber operations. See details in analysis by @euben.bsky.social www.nattothoughts.com/p/provincial...
Provincial Tasking, Cross-Provincial Execution: A Case-Based Look at How China Scales Cyber Operations
How decentralized MSS and MPS tasking and market-enabled, cross-provincial execution by commercial firms shape the scale of China’s cyber operations
nattothoughts.com
In this post, @euben.bsky.social and the Natto Team assess that provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations. nattothoughts.substack.com/p/the-many-a...
The Many Arms of the MSS: Why Provincial Bureaus Matter in China’s Cyber Operations
Provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations
nattothoughts.substack.com
@euben.bsky.social Eugenio’s research explains the elite cyber talent paradox in China - “all people are soldiers” vs “extremely lean.” #Cybersecurity #TalentPipeline #CyberOperations nattothoughts.substack.com/p/few-and-fa...
Few and Far Between: During China’s Red Hacker Era, Patriotic Hacktivism Was Widespread—Talent Was Not
Inside the small, elite circles that powered China’s massive hacker communities in the late 1990s and 2000s.
nattothoughts.substack.com
Microsoft is probing whether a MAPP leak let Chinese hackers exploit a SharePoint vuln pre-patch. In this new piece for Natto, @dakotaindc.bsky.social, @meidanowski.bsky.social & I dig into: 🏛️ China's vuln reporting rules 📉 Which firms joined/left MAPP since 2018 ⚠️ The risks today’s members pose
New: Microsoft is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in SharePoint before they were patched, enabling a global campaign of cyberattacks, according to people familiar: www.bloomberg.com/news/article...
Microsoft Probing If Chinese Hackers Learned of Flaws Via Alert
Microsoft Corp. is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in its SharePoint service before they were patched, acc...
bloomberg.com
In the latest Hooked!, editor @katharinegk.bsky.social ties together some fascinating recent research from @benread.bsky.social , @euben.bsky.social, @winnona.bsky.social, and others on private sector elements of Chinese offensive cyber: bindinghook.com/articles-hoo...
Hooked! #5: A series of new reports and research shows that China’s tech sector is on the offense
A series of new reports and research shows that China’s tech sector is on the offense
bindinghook.com
1/ China’s cyber capabilities didn’t start top-down, they started with raw hacking talent. The new CSS/ETH report "Before Vegas" traces how informal talent shaped China’s cyber ecosystem, moving from online forums to industry leaders (link in thread).
How did China's top APT hackers come to be? Many were early "Honkers" - patriotic hackers who in late 90s launched low-skill cyberattacks against nations deemed disrespectful to China. But once Honkers developed their skills, PLA/MSS came calling. Based on great research by bsky.app/profile/eube...
How China’s Patriotic ‘Honkers’ Became the Nation’s Elite Cyber Spies
A new report traces the history of the early wave of Chinese hackers who became the backbone of the state's espionage apparatus.
wired.com
How has China advanced its AI development to its current state? No single innovation path in AI can be considered definitive. nattothoughts.substack.com/p/debating-c...
Pick Your Innovation Path in AI: Chinese Edition
China’s advances in AI show the effects of a state approach of “introduce, digest, absorb, re-innovate” and years of debate on the balance between market-driven innovation and state-led development
nattothoughts.substack.com
“alignment with CCP priorities offers privileged access to state resources, regulatory favor, and expanded commercial opportunities [to hackers]." NEW Phenomenal report on Chinese civil military fusion and cyber militias by Kieran Green: margin.re/mobilizing-c...
Mobilizing Cyber Power: The Growing Role of Cyber Militias in China’s Network Warfare Force Structure
This report examines how China’s cybersecurity industry fields reserve and militia units in support of the PLA and national mobilization system.
margin.re
🚨 NEW PAPER on the 0day Supply Chain 🚨: I gathered open source data & interviewed Gov employees, VR and china researchers to figure out what the zero day marketplace looks like in the U.S. and how it compares to China. key findings below ⬇️- 0/🧵 www.atlanticcouncil.org/in-depth-res...
Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace
If the United States wishes to compete in cyberspace, it must compete against China to secure its offensive cyber supply chain.
atlanticcouncil.org
To defend, one must first know how to attack” (未知攻,焉知防). This mindset, popularized by a Taiwanese hacker Lin in the 1990s, spread from China's red hackers to CTF teams. Today, it powers China's cyber industry. New piece for @nattothoughts.bsky.social nattothoughts.substack.com/p/defense-th...
Defense-Through-Offense Mindset: From a Taiwanese Hacker to the Engine of China’s Cybersecurity Industry
The belief that offense enables defense in cyberspace, first rooted in China’s 1990s hacker culture, has since permeated the country’s cyber ecosystem
nattothoughts.substack.com
The Natto Team explores the development of China's vulnerability research and discovery skills, starting from the vocational college level. Thanks to @euben.bsky.social @dakotaindc.bsky.social Kristin Del Rosso for their previous research on the topic nattothoughts.substack.com/p/when-a-voc...
From Humble Beginnings: How a Vocational College Became a Vulnerability Powerhouse
Qingyuan Polytechnic's focus on vulnerability studies highlights China's continued efforts in gathering vulnerability resources
nattothoughts.substack.com
The Natto Team continues finding stories of Chinese hackers fascinating as they reveal the motivations behind cyber operations and the evolution of China's information security industry. nattothoughts.substack.com/p/stories-of...
From the World of “Hacker X Files” to the Whitewashed Business Sphere
Jiang Jintao’s journey from hacker to infosec entrepreneur illustrates the blend of ambition, skill, and changes in China's cybersecurity industry
nattothoughts.substack.com
In their latest for #BindingHook, Massimo Marotti, Matteo E. Bonfanti, and Giovanni Faleg of the Italian National Cybersecurity Agency reflect on the process of forming the new #G7CybersecurityWorkingGroup: bindinghook.com/articles-hoo...
Sowing the seeds of enhanced cybersecurity cooperation within the G7
Officials from the Italian National Cybersecurity Agency discuss the challenges and successes of creating the new G7 Cybersecurity Working Group
bindinghook.com
Fascinating to see reference to GRU unit 20728 from FR relative to Russia's offensive cyber program -- as far as I'm aware, a first from a Western service? www.diplomatie.gouv.fr/fr/dossiers-...
Russie – Attribution de cyberattaques contre la France au service de renseignement militaire russe (APT28) (29.04.25)
La France condamne avec la plus grande fermeté le recours par le service de renseignement militaire russe (GRU) au mode opératoire d'attaque APT28, (…)
diplomatie.gouv.fr
Fellow @euben.bsky.social argues that EU member states should reduce strategic #technologicaldependencies on non-EU countries, particularly those deemed high-risk, and enhance proactive #cybersecurity capabilities. bindinghook.com/articles-bin...
Cyber threats are increasingly complex. What can governments do to defend against them?
Virtual Routes fellows look for ways to shrink the gap between cyber threats and defensive capabilities, from regulatory sandboxes to supranational understandings of critical infrastructure.
bindinghook.com
In this piece with @nattothoughts.bsky.social's @meidanowski.bsky.social, we dug into China’s two naming-and-shaming campaigns over the past 30 days—targeting alleged Taiwanese and U.S. hackers amid escalating geopolitical tensions. nattothoughts.substack.com/p/wars-witho...
Wars without Gun Smoke: China Plays the Cyber Name-and-Shame Game on Taiwan and the U.S.
China’s security services have called out hackers of an alleged “Internet Army of Taiwan Independence” and of the U.S. National Security Agency, signaling an increasingly confrontational approach
nattothoughts.substack.com
My question is did state media add mention of US universities in response to the paper @euben.bsky.social and I wrote last year which included circumstantial evidence of hacks by NWPU? www.sentinelone.com/labs/labscon...
LABScon24 Replay | A Walking Red Flag (With Yellow Stars)
Dakota Cary and Eugenio Benincasa explore China's CTF ecosystem, highlighting competitions held by the Ministry of State Security and the PLA.
sentinelone.com
But something weird happens along the way. Someone at Xinhua adds details not in the MPS notice or CVERC report that US universities (Virginia Tech, University of California) were involved. www.reuters.com/technology/c...
It was a matter of time. Less than a month after outing alleged Taiwanese cyber operatives in an unprecedented move for both its tone and detail, China has done the same with alleged NSA operatives—for the first time. The language echoes that of Western reports, though less detailed.
China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents - www.reuters.com/technology/c...
What's happening to @thekrebscycle.bsky.social is disgusting He's one of the most hardworking, dedicated and smart people I'm lucky enough to know, and he showed a LOT of courage when he fought back against attempts to undermine the 2020 election result I hope Americans will stand behind him
We loved having you @weberv.bsky.social, Zoë van Doren, @euben.bsky.social & co! 🙏
It was a real pleasure to speak about #China as a risen cyber power at the @virtualroutes.bsky.social colloquium w Zoë van Doren yesterday. Thanks to thought-provoking comments from @euben.bsky.social and great chairing by Lena Riecke & @partomirzaei.bsky.social.