Skip to content
Dutch Intelligence Warns of Chinese Malware Targeting Edge Devices

Dutch Intelligence Warns of Chinese Malware Targeting Edge Devices

First seen 9 Oct 2026, 16:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 17:38 UTC
  • •Chinese state-sponsored malware targets edge devices, compromising 20,000 globally.
  • •The malware survives firmware updates, making detection and remediation challenging.
  • •Dutch intelligence predicts a significant increase in cyberattacks on edge devices.

Dutch intelligence agencies have reported a surge in Chinese cyberattacks targeting edge devices such as routers and firewalls. A newly discovered malware can survive firmware updates and has compromised 20,000 network appliances globally. The Military Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) issued a warning on October 7, predicting that these attacks will intensify in the coming years. The malware's ability to persist through firmware patches poses a significant risk, as edge devices are for network security and often lack adequate monitoring capabilities. Organizations using equipment from vendors like Fortinet and Cisco are particularly at risk, as these devices are primary targets for espionage. The advisory emphasizes the need for improved security measures to defend against these sophisticated threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2022-12-13
CVE-2022-42475 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-03-23
CVE-2026-3055 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
Dutch intelligence issues advisory
MIVD and AIVD warn of increased Chinese cyberattacks on edge devices, revealing malware that can survive firmware updates.
english.aivd.nl
2026-10-09
Techtimes reports on advisory
Techtimes covers the Dutch intelligence advisory, detailing the malware's capabilities and the risks to organizations.
Techtimes

More articles in this cluster (5)

Following this threat?

Track Salt Typhoon, Coathanger and Cisco in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What devices are affected?
Routers, firewalls, and VPN gateways from vendors like Fortinet and Cisco are primarily targeted.
What should organizations do to protect themselves?
Organizations are advised to enhance their security measures and monitor edge devices closely for signs of compromise.
How severe is the threat from this malware?
The malware's ability to persist through firmware updates and its widespread impact on 20,000 devices indicate a high level of threat.