Skip to content

China blacklists VMware, Palo Alto Networks software over national security fears: report

Sdxcentral January 15, 2026

Chinese firms using services from U.S. and Israeli vendors told to find local alternatives as tech tensions remain high

Cybersecurity software from vendors including VMware, Palo Alto Networks, and Fortinet has reportedly been blacklisted by authorities in China, with local firms told to use alternatives over national security fears.

Reuters reports, citing people briefed on the matter, that the ban also extends to Israeli vendors, with Tel Aviv-based Check Point Software also affected.

It has not been confirmed how many vendors have received notice from the Chinese authorities regarding their use of now-barred software solutions.

Of the four sanctioned firms, each have some form of presence in China. It is unknown how the reported ban will affect those local offerings.

For example, Broadcom boasts six offices in China, while Palo Alto Networks has five in the country, with another in Macau. Both Fortinet and Check Point have offices in mainland China and Hong Kong.

The quartet of now-barred firms are well known at the very least to China-linked hackers.

Broadcom’s VMware, for example, was the subject of attacks from an apparent state- group dubbed Warp Panda last December. The threat actors were found to have exploited a backdoor for VMware vSphere, in particular VMware vCenter servers and VMware ESXI, to grab cloned virtual machine (VM) snapshots for credential extraction and create stealth, rogue VMs.

A second stealthy Chinese cyberespionage campaign dubbed Fire Ant also targeted VMware ESXi and vCenter servers last summer in attacks labeled by cybersecurity firm Sygnia as having demonstrated a “high degree of persistence and operational maneuverability.”

Another apparent China-linked nation-state actor conducting espionage operations was spotted by Palo Alto Networks’ Unit 42 researchers last September. Referred to as Phantom Taurus , the threat actors are believed to have infiltrated networks operated by telecom carriers and government organizations across Africa, Asia, and the Middle East.

The move to ban the group of vendors comes as ties between China and the U.S. are balancing ever more precariously on trade concessions the nations agreed to last October. President Trump is expected to visit Beijing in April for a state visit.

But politics related to technology remain a hot-button issue between the two superpowers.

China wants local firms to use local solutions, with the country’s all-powerful internet regulator, the Cyberspace Administration of China (CAC), banning domestic technology companies from buying AI chips from Nvidia last September.

On the flip side, the Trump administration has sought to further tighten already stringent export controls of AI chips to China, with shipments of Nvidia’s China-specific H200 GPUs approved but only on a case-by-case basis . U.S. lawmakers earlier this week passed a bill that would further limit China’s access to U.S. technology by closing loopholes that allowed Chinese companies to access sanctioned chips by buying or renting them for use on U.S. soil.

There’s also the worrying trend of state- attacks targeting U.S. infrastructure. Following on from the infamous 2024 Salt Typhoon attacks, the same threat actor group recently returned only last week to breach email accounts used by staff on powerful congressional committees.

Emails belonging to staffers on the House intelligence, foreign affairs, and the armed services, as well as systems used by the House China committee, are thought to have been breached in a Salt Typhoon-led attack last December 2025.

Extracted Entities

Attack Types (1)

Campaigns (1)

Countries (1)

Industries (1)

Tools (1)