logo

China caught pushing Vulnerability Reporting Delays down the Memory Hole

ID: cf59aae2-7778-564e-96b7-7b1477ea9768

STIX ID: report--cf59aae2-7778-564e-96b7-7b1477ea9768

Feed Name: Security Ledger

Threat Score
60/100

Date Published: 2018-03-09

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Recorded Future alleges that China’s CNNVD, overseen by the Ministry of State Security, altered original publication dates for at least 267 CVEs (and backdated many others) to conceal reporting delays for high-risk vulnerabilities; the manipulation appears intended to hide evidence that the government may retain or evaluate serious flaws for offensive cyber operations and creates transparency, liability, and compliance risks for organizations relying on CNNVD data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.