Global Situation Board
Actor · non-state · Transnational & Hybrid

Chinese state hackers (Salt/Volt Typhoon)

4High
Assessed 15 September 2026

Assessment

APT31 first deployed the BlueMoon exploit kit, chaining Microsoft Windows and Google Chrome vulnerabilities, on Aug 28, and several other suspected China-nexus espionage clusters adopted it within days. Salt Typhoon's long-running telecom and critical-infrastructure compromise, active since at least 2021 and spanning hundreds of organisations in more than 80 countries, remained unresolved through Sept 15 with no new public advisory.

Recent, assessed

Level history

Threat level after each research review12 September 2026 baseline: level 4; 12 September 2026 weekly review: level 4; 14 September 2026 weekly review: level 4; 15 September 2026 weekly review: level 41234512 September 2026, baseline: level 412 September 2026, weekly review: level 414 September 2026, weekly review: level 415 September 2026, weekly review: level 412 Sep14 Sep15 Septoday

Levels set by research reviews. A level set by hand is shown at the top of the page while it is in force and is not part of this history.

DateLevelReview
2026-09-154Weekly review
2026-09-144Weekly review
2026-09-124Weekly review
2026-09-124Baseline

Latest headlines 1

Matched to this entry by keyword from the pull of 19 Sep, 11:09 UTC. Not reviewed; some may be off-topic.