The images in this article were generated with artificial intelligence. How we publish
The extradition to the United States from Italy of Xu Zewei, accused of belonging to the group of hackers known in the press as Silk Typhoon and linked by the authorities to operations led by the Shanghai State Security Office (SSSB) of the Ministry of Security of the State of China, again focuses on an already known but increasingly complex reality: the mix between geopolitan-wide, private companies that act as "enhancers" and the direct impact on sensitive research, universities and public agencies.
According to the prosecution, the facts attributed to Xu include attacks between February 2020 and June 2021, including gaps in the Belgian university systems to remove information on COVID-19 vaccines and the exploitation of critical vulnerabilities in Microsoft Exchange Server that allowed the implementation of web shells for remote administration. These vulnerabilities, publicly documented as part of the fault chain exploited by the actor traced by Microsoft as Hafnium they caused a massive mitigation response in early 2021 and remain a case study on how a single vector can affect thousands of organizations. More technical details on these failures are available in the vulnerability register (CVE) and in Microsoft's analysis of the Hafnium campaign: CVE-2021-26855 and Microsoft report on Hafnium.

From the legal and diplomatic point of view, extradition from Italy - where the accused was arrested while on vacation - underlines the capacity for international cooperation in cases of cybercrime with state implications, but also opens questions about evidence, right of defence and risk of politicization. Xu has denied his participation and his lawyer confirmed that he pleaded not guilty; the presumption of innocence and the scrutiny of evidence will be key to not becoming a political indictment.
For the academic sector and research organizations, the lesson is clear: biomedical research and academic infrastructure are high-value objectives for actors seeking strategic advantage. Protecting these environments requires not only patches and updates - essential after incidents such as Exchange - but sustainable measures over time: network segmentation, strict control of remote access, verified backup and protocols for the management of credentials and third-party access. In practical terms, the technical recommendations that resonated after the 2021 wave of explosions remain in place and must be part of the governance of institutional cybersecurity.

Beyond technical measures, there are political and economic implications: using national companies for covert operations complicates the attribution and lower the threshold between intelligence activities and criminal offences, causing diplomatic tensions and potential policy or punitive reprisals. The international community and policy makers must balance the punitive response with mechanisms that reduce the scale and impact of these operations, including transparency agreements on security of critical infrastructure and channels of judicial and police cooperation.
If you manage critical systems or sensitive research, act now: make sure that the mail servers and collaboration platforms are first-time, active multifactor authentication in all management accounts, deployment of anomalies and search for commitment indicators related to web shells, and coordinate with local authorities and security providers on any suspicion of intrusion. For individual users, keeping up-to-date software, using password and MFA managers, as well as monitoring official incident communications, reduces the risk of being a vector of a major attack.
The case of Xu Zewei will be, in addition to a criminal procedure, an indicator of how international responses to the covert cyberwar are evolving: if extradition ends in conviction, it could strengthen cooperation and pressure on networks that act as providers of offensive capacity; if the defence is able to dismiss attribution, it will serve as a reminder of the evidentiary difficulties in state-sponsored attacks. Meanwhile, the combination of technical surveillance and prudent public policies is the best defence to mitigate the damage these campaigns can cause in research, business and citizens.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...