EXCLUSIVE: How the track foreigners in China - We got rare access to demo system developed by the Ministry of Public Security in China for the prefecture of Zhangjiakou, to track and surveil foreigners visiting or being residents ( actually it applies to most nationals as well, but in this case it seems to be aimed at foreigners ). It is officially known as "Dynamic control platform for overseas personnel". 1/12
How can the surveillance-state backfire in China ? With social engineering campaigns by criminals.
Here we have an Android app that tries to impersonate an official app provided to members of the CN police by the looks of it according to its website ( 110GongAn[.]com). It is not on the Playstore, but can be downloaded via a website.
It seems to impersonate some kind of service app, of a type that has been gaining popularity in the past years to give the police force in China access to services from their cellphones. 1/3
PSA: @TencentGlobal is aggressively scraping the Internet to build yet another AI slop chatbot, DDoSing many websites in the process.
We've found that, as of last week, their scraping bots can now solve Cloudflare challenges and behave like real users while ignoring robots.txt. In the last 24 hours alone, our website received more than 3 million successful requests from Tencent bot IP addresses, plus another 1 million that were blocked by Cloudflare challenges.
These recurring DDoS attacks from Tencent have been going on for over a year, and we have been constantly adjusting our firewall rules to filter them while trying not to impact Tencent's real users. Because that is no longer possible, we're now fully blocking Tencent IP addresses, starting with ASN 132203. We recommend other sysadmins do the same.
Other ASNs displaying similar abusive behaviour will also be fully blocked from our services.
We'd also like to thank @Cloudflare for sponsoring us with Project Alexandria as of 2025, giving our sysadmin the tools to keep RPCS3's online services running without service disruptions.
German police apparently is using AdTech data they acquired via data brokers to track potential targets, against regulations ( German article ): https://t.co/y774v6VOXW
The problem is that many such decisions are taken in the past, as the EU's bureaucracy is slow and cumbersome. But the world is changing too fast, so this legacy stuff is increasingly becoming a problem ( despite it not even be implemented at times ).
❗️ The EU's digital identity wallet apps require an Apple or Google account to function. A sovereign European ID system that can't run without US Big Tech. 😂
• Officials say Apple/Google were chosen "for security reasons" and cover the largest user base.
• "Other ecosystems" support is only being studied, not built.
• EU wants every state to have a working wallet by year-end. No country looks set to make it.
I mean, the Geedge leak is now almost a year old, many aspects were already reported on outside the standard press channles, so a little bit late by thr NYT to jump on that band wagon but good that the story still gets traction.
Beijing is officially weaponizing artificial intelligence to punish citizens for thoughts they have not even voiced yet.
A bombshell New York Times report has unmasked a terrifying evolution in digital tyranny, detailing the shift from punishing dissent to predicting it before it happens. Analyzed by researchers at Vanderbilt University, a massive data leak from the Beijing-based tech firm Geedge Networks reveals that China is actively developing AI-driven predictive surveillance to neutralize political risks. The company has deep ties to Fang Binxing, the infamous father of China's Great Firewall, and is moving far beyond passive internet censorship into the realm of preemptive control.
The leaked documents show that these new systems utilize Large Language Models to synthesize data at scale. By aggregating real-time internet browsing histories, tracking physical movements via cell tower records, and mapping out social media connections, the AI builds comprehensive citizen profiles. It then generates political risk scores to flag individuals who might become critics of the government, allowing the state to intervene based entirely on inferred intent rather than actual actions.
This dystopian toolkit is already being exported as a commercialized service to authoritarian regimes aligned with Beijing's Belt and Road Initiative. The leak exposed that Geedge’s flagship product, which functions as the Great Firewall in a box, was deployed by the military junta in Myanmar to locate pro-democracy activists, block social media, and trigger regional internet blackouts that led to targeted arrests. Similar mass surveillance deployments capable of deep packet inspection and tracking citizen reputation scores have been uncovered in Pakistan and Kazakhstan.
Fortunately, the leaked files also reveal a critical vulnerability in Beijing's digital panopticon. United States export controls on advanced semiconductors have successfully starved Geedge of the high-end computing power required to scale these predictive AI models. Forced to pivot to less efficient tech due to chip shortages, their progress has been significantly slowed. This serves as a stark reminder to Western policymakers that maintaining tight semiconductor sanctions is the primary line of defense keeping this predictive surveillance grid from expanding globally.
#UnveiledChina #PredictiveSurveillance #DigitalAuthoritarianism #GeedgeNetworks #GreatFirewall #Geopolitics #AICensorship #NationalSecurity
It should be said, it tries to also target the "com.binance[.]dev" package on the target device...and goes to work via some sort of Injection when a certain screen is opened.
Haha. So they blocked the article cause it held "pornographic" content. For context, it was an article about how to track illegal pornographic content on the Chinese internet.
Interesting little write up from a CN cyber security researcher on how to interconnect different sources and indicators, combine them to one "fingerprint", hack-back and "exploit" Redis: "Then I used Redis to search for usable data and found the backend login accounts and cached MD5-encrypted passwords!" - https://t.co/ia7G7TH5Vc
We know what probably happened.
From what we see publicly, NightmareEclipse doesn't communicate well, is emotionally immature, and appears to want to extort Microsoft.
Almost certainly, this played a part in the conflict between them and Microsoft -- it's probably as much NightmareEclipse's fault as Microsoft's.
With that said, everything Florian says is correct. It doesn't excuse Microsoft's failures. They are supposed to be the responsible one,
When there is miscommunication or dispute, it's always allowable to drop 0day, regardless whose fault it is. It's Microsoft's job to avoid that, even when they really aren't at fault for the miscommunication.
But Microsoft has convinced themselves of the opposite, that "responsible" disclosure means only the responsibilities of the vuln finder.
Vuln finders have no responsibility. Dropping 0day is responsible. Responsible companies don't have so many bugs.
We let industry subvert the disclosure process. Instead of working to secure their code, vendors have tricked people into believing in the myth of "responsible disclosure", that vendors should be given time to fix and patch their bugs so they are never to blame for the bugs to begin with.
That's why you have customers still buying Fortinet appliances even though their bugs continue to be major sources of customers getting hacked. Customers shrug their shoulders: as long as Fortinet has a vulnerability disclosure program and releases patches, they aren't responsible for when hackers keep breaking into their boxes.
This is garbage. Vendors are still responsible for preventing bugs in the first place, a responsibility that doesn't go away just because they patch.
Regardless of what happened, Microsoft's threats are a gross violation of ethics in the industry.