Cybersecurity Hacking News

China-linked operators target trusted infrastructure and accelerate AI-enabled attacks

China-linked operators target trusted infrastructure and accelerate AI-enabled attacks

QTFY-linked operators reportedly used proxy infrastructure, compromised networks, IoT devices, and large-scale scanning against U.S. government targets before an FBI disruption. Fire Ant reportedly compromised IOS XR routers, hid activity, harvested TACACS credentials, and used trusted infrastructure downstream. Recent reporting and commentary emphasize AI-accelerated reconnaissance, phishing, credential theft, and evasion, although fully autonomous attacks remain unconfirmed.

Sources (3)
Updated Sep 8, 2026