Security Affairs
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions|Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data|U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog|Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients|WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover|Hackers Impersonate IT Support to Breach Leading Financial Companies|Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case|Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access|AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam|Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records|Ransom Cartel Leader Sentenced to 16 Years in U.S.|Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident|Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions|Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data|U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog|Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients|WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover|Hackers Impersonate IT Support to Breach Leading Financial Companies|Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case|Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access|AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam|Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records|Ransom Cartel Leader Sentenced to 16 Years in U.S.|Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions

China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing […]

Palo Alto Networks Palo Alto Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS FlawGlobalProtect CVE-2026-0257

China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe.

China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing national security law and cybersecurity law as the basis for the review, and offers essentially nothing beyond that.

“To ensure the safe and stable operation of critical information infrastructure, prevent cybersecurity risks and vulnerabilities, and safeguard national security, in accordance with the National Security Law of the People’s Republic of China and the Cybersecurity Law of the People’s Republic of China, the Cybersecurity Review Office, following the Cybersecurity Review Measures, has conducted a cybersecurity review of Palo Alto Networks’ products sold in China.” the regulator says.

That’s the entire public justification. No specific vulnerability named, no incident referenced, no timeline for when findings might land. Palo Alto Networks told The Register it maintains high standards across its global operations and that, for now, there’s no impact on its ability to serve customers or deliver products in the region.

The situation resembles China’s 2023 security review of Micron, which was announced without warning. Weeks later, Beijing deemed Micron’s products a security risk for critical infrastructure, effectively restricting sales, but provided little explanation. Micron eventually withdrew its data center and server products from China, losing billions in annual revenue while local chipmakers gained new opportunities.

Micron’s story offers one genuinely reassuring data point for Palo Alto, if it’s any comfort: getting banned from a major market didn’t permanently damage the company. The AI boom drove memory prices high enough afterward that the China restriction barely shows up in Micron’s financials today. Getting frozen out of a market stings a lot less when the rest of the world is buying everything you can produce anyway.

China has already been pushing companies away from foreign cybersecurity products: in January, authorities reportedly told Chinese firms to stop using security software from a list of U.S. and Israeli vendors that included Palo Alto Networks, Fortinet, Check Point, CrowdStrike and others, encouraging the replacement of those products with domestic alternatives. Chinese vendors such as Huawei and H3C have increasingly positioned their own firewalls and security platforms as alternatives to foreign products, while other domestic companies are expanding across the cybersecurity market. H3C, for example, openly promotes its security products as replacements for overseas technologies.

That makes the Palo Alto review more than a simple technical investigation. It fits a broader strategy in which cybersecurity and national security are increasingly intertwined with China’s push for technological self-reliance.

For Palo Alto, the immediate financial impact is difficult to measure because the company does not separately report China revenue, but restrictions could still create an opening for domestic competitors while adding another layer of uncertainty for Western technology companies operating in the country.

There is also a wider geopolitical dimension. Beijing has repeatedly framed foreign technology as a potential national-security risk, while Washington and its allies have taken similar measures against Chinese and Russian vendors, including Huawei, ZTE and Kaspersky. The United States, for example, banned Kaspersky’s cybersecurity and antivirus products over national-security concerns, arguing that the software created risks because of its ties to Russia. The Palo Alto case therefore sits within a much larger cycle of reciprocal distrust, in which cybersecurity products are increasingly treated not only as commercial technologies but also as potential strategic assets.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, China)