👩🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔♂️ A friendly human may check it before it goes live. More news here
🧔♂️ A friendly human may check it before it goes live. More news here
Chinese-linked hackers target key US House committees: report
Chinese hackers accessed email accounts of staff on several key US House of Representatives committees, according to a Financial Times report citing sources familiar with the matter.
The affected committees reportedly include those focused on China, foreign affairs, intelligence, and armed services.
The cyber espionage campaign, called Salt Typhoon, is a top concern among US cybersecurity officials.
Authorities allege the group is prepositioning itself to paralyze US critical infrastructure in the event of conflict.
Beijing has denied involvement, and the White House did not comment.
🔗 Source: Reuters
🧠 Food for thought
Implications, context, and why it matters.
Campaign moves beyond email toward alleged infrastructure prepositioning
- Salt Typhoon differs from Storm-0558’s 2023 spying that hit U.S. government email 1. Storm-0558 used stolen credentials to take data 2. It also forged authentication tokens (digital keys used to verify identity 3) then reached 22 organizations plus more than 500 people 4. Storm-0558 remained inside for at least six weeks and downloaded some 60,000 State Department emails 4.
- Authorities say the group plants footholds in U.S. critical infrastructure like power grids, telecom, and pipelines to enable disruption during a potential conflict. Reported targets include House committees that oversee China policy and foreign affairs plus intelligence and armed services.
Federal agencies speed CISA SCuBA adoption, fueling implementation work
- Vendors and managed service providers can bundle around CISA’s Secure Cloud Business Applications (SCuBA) baselines (recommended security settings for cloud apps) to meet Binding Operational Directive 25-01 deadlines 5. Agencies must deploy SCuBA tools by April 2025 and implement policies by June 2025, which drives demand for Microsoft 365 configuration work.
- SCuBA reaches the private sector and federal/state/local/tribal/territorial governments beyond agencies 6. CISA’s ScubaGear tool has over 30,000 downloads 6 while misconfigured SaaS tenants opened the door in 30% of cloud attacks in early 2024 6. The Cyber Safety Review Board (CSRB) said Microsoft’s security culture needs an overhaul 4 opening room for third-party tools with independent threat detection and compliance checks across Microsoft 365 including Teams, SharePoint, and Power Platform 5.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




