Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Congress Runs a Fake China-Taiwan Cyberwar and It Isn't Pretty

Members and staff from the House Homeland Security Committee and the House China Select Committee sat through a simulated Taiwan crisis Tuesday, hosted by the Center for Strategic and International Studies, according to Defense One. The scenario wasn't real. The questions it raised are.
The exercise put Republican Reps. Eli Crane of Arizona, Michael Guest of Mississippi and Michael McCaul of Texas in the room alongside Democratic Rep. Shri Thanedar of Michigan and Puerto Rico Resident Commissioner Pablo José Hernández, a Democrat, per Defense One's readout.
The setup: ambiguity by design
The scenario opens with China launching a massive military exercise around Taiwan in the summer of 2027. U.S. officials in the simulation can't tell if Beijing is coercing Taipei, imposing a quiet blockade, or staging for a full invasion, according to the readout given to reporters before the simulation began. Beijing never uses the word "blockade" in the scenario, but the effect is the same: Taiwan gets quarantined anyway.
Real-world crises rarely announce themselves with clean labels, and the exercise forces lawmakers to make decisions without the clarity a headline would give them.
Then the hackers show up
Intelligence analysts in the simulation suspect Chinese hackers are already inside American ports, freight rail systems and airports, according to Defense One. Some of the intrusions cause immediate chaos. Others appear built to sit quietly and get triggered later, when it matters most, the readout says.
Lawmakers then have to decide which networks to defend first, how much to loop in private-sector infrastructure operators who own most of that infrastructure, and whether surging U.S. forces toward the Pacific would deter Beijing or hand China an excuse to escalate.
None of those are easy calls. Defending everything at once isn't realistic. Trusting private companies with sensitive threat intelligence carries its own risk. And every visible U.S. military movement is a signal China's leadership will read and react to.
AI made it worse, and it was supposed to
The exercise built in AI-enabled attacks: stolen credentials used to move through networks, interference with freight routing and logistics systems, and an AI-generated disinformation campaign. The final scenario centered on a prompt injection attack, where an adversary tries to trick an AI system into ignoring its own safeguards and following hostile instructions instead.
McCaul flagged the stakes bluntly. "This committee has been briefed extensively on our latest AI capabilities, Anthropic in particular, the Mythos model, and the amount of destruction that Mythos can do if it's in the wrong hands," he told participants, according to Defense One. "And we know China is three to five months behind us. That's not very long."
McCaul's claim about China trailing U.S. AI capability by three to five months is his characterization of committee briefings, not an independently verified public assessment. It comes from a sitting member of Congress with direct access to classified briefings on the subject. A three-to-five-month gap in frontier AI capability is not a comfortable margin when the technology in question can be repurposed for offensive cyber operations against critical infrastructure.
McCaul also offered a broader framing before reporters were asked to leave so lawmakers could speak more freely: cyber "is always going to be a leader in any kinetic war."
What's actually proven versus what's assumed
CSIS ran a tabletop simulation, not a live-fire test. No actual Chinese cyberattack on U.S. ports or rail systems has occurred as of this writing. The 2027 Taiwan invasion timeline referenced in the scenario is a planning assumption long used by U.S. Indo-Pacific Command officials, not a confirmed Chinese Communist Party decision or deadline.
The genuine, unresolved question coming out of this exercise is one Congress itself hasn't answered: how much authority should private companies running America's ports, rail lines and airports have to act on classified threat warnings, and how fast can that information legally and practically reach them before an attack, not after one.
What happens next
CSIS has not announced whether it will publish a full after-action report from Tuesday's exercise or run additional rounds with other congressional committees. Given that both the House Homeland Security Committee and the House China Select Committee sent members, further legislative action, likely around critical infrastructure cybersecurity funding or public-private information-sharing rules, is a plausible next step to watch for in the coming months.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.