Cyber cold war heats up: state hackers, tech bans, and the race for digital sovereignty

The Hacker News ↗

The gist

A new cyber Cold War is raging, as state-backed hackers, tech bans, and quantum-fueled arms races turn digital infrastructure into the ultimate battleground for global power.

What to know

  • Russian and Chinese cyber operations have escalated, breaching Western critical infrastructure and government systems with advanced zero-days and long-term infiltration campaigns.
  • Nations are racing for digital sovereignty—banning foreign tech giants like Huawei, ZTE, and Palo Alto Networks, while pouring billions into homegrown cyber defenses and regulatory crackdowns.
  • AI and quantum tech are turbocharging cyber offense and defense, forcing governments to automate, innovate, and overhaul strategies or risk being outpaced by adversaries.

State Hackers Go Stealth

Russian and Chinese cyber operatives are embedding themselves deep within Western infrastructure, using zero-days and legitimate admin tools for long-term espionage and sabotage while blurring the lines between peace and conflict.

State-backed cyber operations have reached new heights of sophistication and strategic intent, with both Russia and China deploying advanced tactics to infiltrate and destabilize critical infrastructure and government systems across the West. Russian groups such as Sandworm and APT28 have escalated their campaigns by targeting distributed energy resources and leveraging destructive malware like DynoWiper, as well as exploiting zero-day vulnerabilities purchased from underground markets—sometimes for up to $300,000 per exploit. Meanwhile, Chinese actors, notably Volt Typhoon, Salt Typhoon, and UAT-8837, have conducted extensive pre-positioning within U.S. and allied critical infrastructure, using zero-days like Sitecore CVE-2025-53690 and sophisticated supply chain infiltration, while also penetrating high-level government communications in the UK and U.S. Congress. These operations are marked by a shift toward long-term intelligence positioning and the use of legitimate administrative tools to evade detection, prompting urgent modernization efforts by Western cybersecurity agencies and highlighting the blurred boundaries between espionage, sabotage, and preparation for potential conflict.

Sources
The Hacker NewsThe Hacker NewsIntruvent EdgeThe Hacker NewsTechcrunchCISO Talk by James Azar

Grid Vulnerabilities Multiply

The explosion of digital endpoints in critical infrastructure—especially energy—has created countless new attack vectors, turning every smart device into a potential weak link for state-backed hackers.

The rapid digitalization and decentralization of critical infrastructure—particularly energy grids—has dramatically expanded the attack surface for cyber threats. Modern grids, reliant on precise frequency balance and interconnected devices like solar panels, wind turbines, and EV charging stations, now present countless remote access points for potential attackers. As seen in the UK, even minor frequency deviations can trigger catastrophic equipment failures, and the proliferation of digital endpoints means that each new device becomes a potential vulnerability, compounding systemic risk across national infrastructure.

While fears of hardware 'kill switches' embedded by foreign suppliers like China remain largely theoretical, the real danger lies in the control and oversight of smart infrastructure by external firms. Instead of a single catastrophic off-switch, the risk is more insidious: foreign operators with legitimate remote access can exploit complex digital machinery for targeted manipulation or espionage. This nuanced threat underscores the importance of scrutinizing not just the components themselves, but who ultimately holds the keys to their operation.

Recent years have seen a surge in state-sponsored cyberattacks targeting critical infrastructure, with incidents like the Russian attacks on Ukraine’s grid (2015-2016), the Colonial Pipeline ransomware event (2021), and the 2025-2026 Sandworm campaign against Poland’s distributed energy resources. These attacks have evolved from targeting centralized power stations to exploiting vulnerabilities in geographically dispersed, less-secured assets such as wind farms and solar installations. The December 2025 attack on Poland, timed to the anniversary of Sandworm’s Ukraine operation, marked the largest such assault on a NATO member and demonstrated how destructive malware like DynoWiper could threaten the safety of hundreds of thousands of civilians.

Supply chain vulnerabilities have emerged as a critical front in the cybersecurity battleground, with attackers exploiting zero-day flaws in widely used platforms (such as Sitecore CVE-2025-53690 and WinRAR CVE-2025-8088) and exfiltrating DLL-based shared libraries to potentially compromise software at scale. These sophisticated campaigns, often orchestrated by Chinese and Russian state-backed groups, leverage open-source tools for credential theft and persistent access, raising the specter of trojanized software infiltrating national infrastructure. The resulting systemic risks have prompted urgent guidance from Western governments and catalyzed multi-billion-euro hardware replacements, as seen in the EU’s aggressive phase-out of high-risk telecom suppliers like Huawei and ZTE.

The vulnerabilities extend beyond energy grids to government communications, as evidenced by Chinese espionage operations that breached Downing Street officials’ mobile phones from 2021 to 2024 and infiltrated Congressional committee staff emails in the U.S. These incidents highlight the acute risks posed by inadequate mobile security and the need for robust compartmentalization of sensitive information. As one expert warned, the compromise of government communications networks exposes the very nerve centers of national security decision-making to foreign manipulation and surveillance.

Sources
Notes on GrowthTechcrunchIntruvent EdgeThe Hacker NewsCISO Talk by James AzarCISO Talk by James Azar

Sovereignty or Remote Control?

Nations are scrambling to reclaim digital sovereignty as foreign tech firms retain remote access to vital infrastructure, making economic leverage and covert manipulation bigger threats than mythical hardware 'kill switches.'

The quest for digital sovereignty has shifted the focus from the physical components of critical infrastructure to the software and remote access controls that underpin them. While the specter of hidden 'kill switches' in every imported inverter or turbine remains largely a myth, the real vulnerability lies in targeted manipulation of high-value equipment—especially when foreign manufacturers, such as those from China, retain legitimate remote access. This nuanced threat landscape has prompted nations to scrutinize not just what is installed on their grids, but who ultimately holds the digital keys.

By early 2026, digital sovereignty has become a rallying cry for governments worldwide, prompting a wave of bans and regulatory crackdowns targeting foreign technology providers. China’s high-profile exclusion of U.S. and Israeli cybersecurity giants like Palo Alto Networks, CrowdStrike, and Check Point is less about immediate risk and more about wielding economic leverage in global negotiations—a move described as 'Wall Street chess, not cybersecurity checkers.' Meanwhile, the European Union is scrambling to replace Huawei and ZTE hardware in its 5G networks, mandating vendor diversification and multi-billion-euro swap-outs in a belated but determined bid to reclaim control over its digital infrastructure.

The expanding digitalization and decentralization of sectors such as energy and transportation have dramatically increased the attack surface for potential cyber threats, making digital sovereignty a matter of national security. Incidents like Australia’s investigation into Chinese-made electric buses for telemetry backdoors underscore the risks of remote control vulnerabilities embedded in foreign technology. As James quipped, 'If you buy cheap, you’re not getting a deal—you’re buying someone else’s remote control,' highlighting the urgent need for independent security vetting and tighter regulatory oversight.

Cybersecurity is no longer a purely technical concern; it has become a central instrument of global policy and economic maneuvering. The global crackdown on cybercriminal groups like Black Basta, alongside sweeping bans and regulatory actions, illustrates how nations are using cybersecurity both to protect their digital borders and to project power. As 2026 unfolds, 'security is sovereignty' has become more than a slogan—it's a guiding principle shaping the new world order of technological alliances and rivalries.

Sources
Notes on GrowthCNBC - TechnologyCISO Talk by James AzarCISO Talk by James AzarThe Prof G Pod – Scott GallowayCISO Talk by James Azar

AI and Quantum Escalate Arms Race

The fusion of AI and quantum tech has supercharged cyber offense and defense, forcing governments into a relentless algorithmic contest where falling behind is not an option.

By early 2026, the convergence of AI and quantum technologies has fundamentally reshaped the global cybersecurity landscape, accelerating both the discovery and exploitation of vulnerabilities. This shift has transformed cyber operations into a relentless arms race, where nations and their algorithms compete to outpace one another in both offense and defense. Security leaders, recognizing the existential stakes, are now compelled to overhaul their operational, intelligence, and policy frameworks to keep pace with adversaries wielding ever-more sophisticated AI-powered tools.

As the arms race intensifies, the notion of waiting for a technological 'silver bullet' has become dangerously obsolete; instead, rapid and strategic adoption of AI is now a national security imperative. Automation and rigorous testing have emerged as essential pillars of modern cybersecurity strategies, enabling organizations to adapt quickly and maintain an edge in an environment where threats evolve at machine speed. This continuous, high-stakes contest leaves little room for complacency, as even a momentary lapse in innovation can mean ceding critical ground to adversaries.

Sources
ChinaTalkCyberWire DailyChinaTalk

Cybersecurity Demands Radical Change

Massive government investments and tougher laws are now seen as essential, as outdated systems and weak accountability have left even top nations struggling to keep up with escalating cyber threats.

By early 2026, the UK government’s £210 million pledge to its new National Cyber Action Plan signaled both a dramatic escalation in investment and a candid admission: cyber risk in the public sector remains 'critically high.' Despite years of effort, officials conceded that the ambitious 2030 goal of securing all government bodies from cyber threats is now out of reach, underscoring the need for more robust legislative and operational reforms to address persistent vulnerabilities and the evolving threat landscape.

The shortcomings of previous cybersecurity strategies—hampered by non-binding guidance and outdated legacy IT systems still present in over a quarter of UK government operations—have prompted a shift toward greater accountability, with senior leaders now facing personal responsibility for cybersecurity outcomes. This pivot reflects a broader recognition that effective defense requires not just technical upgrades but also cultural and structural change at the highest levels of leadership.

Globally, the escalation of cyber threats from adversaries like China and Russia has driven calls for legislative modernization and more aggressive defense postures. In the US, experts and industry leaders such as CrowdStrike have pressed Congress to overhaul outdated cyber laws, advocating for clearer agency roles, faster information sharing, and accelerated infrastructure takedowns to enable a 'forward-leaning' defense. Meanwhile, UK officials warn that without visible offensive cyber capabilities, the nation risks becoming a 'cyber punching bag,' highlighting the growing consensus that deterrence through credible response is as essential as regulation.

International cooperation and cross-sector partnerships have become linchpins in the fight against sophisticated cyber threats. The Five Eyes alliance’s intelligence sharing was pivotal in uncovering China’s 'Salt Typhoon' espionage campaign targeting UK officials, while joint operations between U.S. Cyber Command and private industry—embodied in initiatives like CyberCom 2.0—aim to root out persistent intruders in critical infrastructure. As WEF panelists emphasize, urgent global partnerships, supply chain security, and AI oversight are now seen as indispensable to tackling the complexity and scale of modern cyber risks.

The relentless pace of vulnerability exploitation—evident in the exposure of nearly 60,000 hosts to CVE-2026-21858 and the Kimwolf botnet’s infection of over two million Android devices—has forced governments and industry leaders to prioritize timely patching, robust security configurations, and legislative reforms to enforce standards. Investment in resilience, from network segmentation to restore plan rehearsals, is now standard practice for critical infrastructure operators, who must contend with increasingly sophisticated criminal tactics and the unpredictable fallout from geopolitical instability within adversary cyber commands.

Cybersecurity has become inseparable from national sovereignty and global power, driving a wave of strategic decoupling in technology supply chains and alliances. As one analyst put it, 'Cyber is no longer just a technical battlefield; it’s an instrument of global policy and economic control.' For CISOs and policymakers alike, this means aligning defense strategies not just with compliance, but with the shifting realities of 21st-century geopolitics—where security is sovereignty, and the front lines are digital.

Sources
TechRadarN2K NetworksCISO Talk by James AzarWorld Economic ForumThe Hacker NewsCISO Talk by James Azar

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.