Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.
Dutch Intelligence Forecasts Sharp Rise in Chinese Hacking of Firewalls and VPNs; Beijing Denies It

The Dutch Military Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) issued a joint cyber advisory on Wednesday, Oct. 7. The core prediction: attacks by Chinese hackers through vulnerable "edge devices" will increase strongly over the next few years.
Edge devices are the boxes that sit between an organization and the open internet. Firewalls, VPN gateways, proxies and login portals all qualify. The advisory was prepared with the Dutch National Cyber Security Centre (NCSC-NL).
Source code and AI
The two agencies say Chinese hackers know these devices in intimate detail. They study Western hardware and software closely and, in some cases, have obtained non-public source code, the advisory says. That lets them hunt for vulnerabilities the manufacturer does not know about.
The advisory says some of that code was obtained through cyber espionage. It does not name the products or companies affected.
The agencies also say China's commercial and research sectors support the effort. According to the advisory, some Chinese firms research flaws in Western products and some sell ready-made attack tools. The Dutch also point to a 2021 Chinese law requiring people to report flaws they find, and to training programs aimed at hacking edge devices.
Then there is AI. The services say it helps hackers find and exploit vulnerabilities faster than before, and turn newly disclosed flaws into working attacks more quickly. The advisory says risk climbs sharply once a flaw becomes public. It also says Chinese hackers often use old, known flaws, not just secret ones.
Dutch Defense Minister Dylan Yesilgöz repeated the message on X. "Artificial intelligence allows hackers to find and exploit vulnerabilities more quickly. Chinese hackers are also taking advantage of this," she wrote.
Last month, NCSC director Matthijs van Amelsvoort warned that AI is automating the attack chain, from finding vulnerabilities to exploiting them. Dutch authorities believe attackers do not need the most advanced models; widely available tools may be enough.
The Coathanger precedent
The forecast builds on a case the Dutch made public in early 2024. Chinese state hackers broke into a Dutch military network by exploiting a flaw in Fortinet's FortiGate firewalls and planted a spying tool called Coathanger.
Dutch authorities later said the campaign was far larger than first thought. It hit at least 20,000 FortiGate devices worldwide, including those at Western government departments, diplomatic missions and defense contractors. The hackers began exploiting the flaw at least two months before Fortinet announced it.
The Dutch network involved was used for unclassified research and was standalone, so the wider defense network was not affected.
Beijing's response
The Chinese Embassy in the Netherlands rejected the advisory in a spokesperson's statement. It said the report "seriously damages China's image" and is "full of untruthful words and baseless accusations."
"China expresses its strong dissatisfaction and resolute opposition to this," the embassy said. It added that China is "one of the primary victims of cyberattacks" and has consistently cracked down on malicious cyber activity in accordance with the law. The embassy urged Dutch authorities to "stop baseless accusations under the pretext of cybersecurity."
The MIVD had already flagged the rise in Chinese edge-device hacking in its most recent annual report. The AIVD notes that many hacking groups target these devices, but says Chinese hackers in particular are known for the approach.
What the agencies want organizations to do
The advisory pushes "defense in depth":
- Install security updates promptly.
- Use multi-factor authentication across the organization.
- Segment the network.
- Encrypt data at several layers.
- Run custom-configured firewalls and intrusion detection.
- Diversify equipment suppliers, so a flaw in one vendor's products cannot compromise multiple layers of security at once.
The agencies also stress logging, and their language is blunt. "Practice shows that victims of a cyberattack are often unable to provide the necessary log files," they say. Logs are often not stored at all, or kept for a very short time. Incident logs are also frequently stored locally on the compromised device, where an intruder "can alter or delete" them.
The fix they recommend is centralized logging, stronger monitoring and "forensic readiness," meaning an organization can launch a forensic investigation immediately after a breach. They also recommend that staff practice those investigations periodically.
The advisory is public, but the intelligence behind its claims about source-code theft is not. The agencies have not said which vendors' code was taken. Whether any manufacturer confirms it is an open question.
The Dutch recommendation that organizations hold their own logs off the device is the concrete step the agencies say would leave victims able to prove what happened.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.