New Natto piece examines the cyber ops and contractors behind China’s efforts to target critics abroad, and how the tools and capabilities behind these campaigns circulate across China’s cyber ecosystem, as illustrated in the chart below. Link in thread.
Where does China stand in AI-driven vulnerability discovery? One company claims its AI-assisted bug discovery operates at a scale similar to that claimed for Claude Mythos. What does that actually look like?
More on Natto Thoughts (link in thread).
After 2 years in the dark, the Tianfu Cup is back. The event – China’s most prestigious 0-day hacking contest – resurfaced with little visibility.
The website was live only briefly, but we got to it in time. New Natto analysis (link in thread) digs into 4 key developments:
This piece traces the shift from earlier, more provincially bounded operational models toward cross-provincial collaboration with legitimate cybersecurity businesses, and explores why these firms are concentrated in a small number of provinces 👉 https://t.co/95bueNxLKO
How do China’s cyber operations scale to a near-nationwide level? While provincial MSS/MPS bureaus remain core nodes of authority and tasking, a detailed case study demonstrates how companies can enable cross-provincial operations at scale (link in thread)
Intense competition, rapid innovation, and strong state involvement define the overall trends in China’s cybersecurity industry for 2025. See our latest analysis:
https://t.co/qWqmVo25wM
From attack–defense thinking to vulnerability research and exposed threat actors, the Natto Team explored key aspects of China’s cyber ecosystem in 2026.
https://t.co/TGCOvNgHIV
China’s Ministry of State Security (MSS) is not a monolith, but highly provincialized. Its provincial bureaus function as the operational nerve centres of state cyber ops. In a new piece, @MeiDanowski and I examine their roles and patterns of specialization (link in thread)
The Natto Team examines the leaked incident from Knownsec’s perspective to explore the role that elite Chinese cybersecurity companies play in building the country’s cyber capabilities.
Western govts grapple w/how the private-sector could be better integrated into state cyber ops. In China, many ops flow through "attack-defense labs," which blend commercial work w/state-linked activity.
This piece w/@MeiDanowski examines these labs & their state links (link👇)
Researcher @sickcodes found a vulnerability in TCL TVs and reached out to TCL. What happened next became a masterclass in what NOT to do-eventually, what TO do.
New analysis from Natto Thoughts - how a single disclosure reshaped China’s approach to cybersecurity and control.
The Natto Team explores how APT27, HAFNIUM, and Silk Typhoon highlight the complexities of tracking threat actors and their real-world identities and why understanding the humans behind the keyboard matters.
The Natto Team examines the Joint Advisory and highlights how government agencies navigate the complex web of threat actors, corporate suppliers and state intelligence Chinese state cyber operations. See Natto Thoughts analysis 👇
Very excited to have the opportunity to work with @eubenincasa and present our research at @labscon_io - the best conference of year as many people say.
Off to @labscon_io in the Arizona desert next week to dive into China cyber research with @MeiDanowski 🌵😎 Looking forward to seeing everyone there and catching some great research