ChinaWatch
Strategic, operational and tactical feeds tracking power shifts, militancy, defense, economics, migration and policy across the Indo-Pacific and the Taiwan Strait.
AI Daily Briefing
Intelligence Community Directive 203 · Generated from last 24h reporting
Current reporting covers 15 items across cyber, military, power, concentrated in China (national), South China Sea, Taiwan, including 2 critical and 6 high severity entries. Lead development: Salt Typhoon breach of US telecom carriers expands — lawful-intercept systems compromised (WSJ / Federal Bureau of Investigation (FBI)).
24-hour judgment
China-related reporting in the last 24 hours indicates 8 priority events (2 critical, 6 high) across 9 activity domains, with China (national) as the most active axis.HIGH [1] [2] [3]
China (national) concentrates the bulk of priority reporting (4/8, 50% of priority traffic)HIGH [1] [2] [3]; Cyber Activity is the dominant activity domain at 20% of all reportingMODERATE.
Cyber activity attributable to PRC-nexus actors is present in the window (3 reports, 3 priority)MODERATE; Diplomatic signalling continues at a measurable tempo (3 engagements)MODERATE; We assess the next 24–72 hours will likely sustain elevated tempo absent a de-escalatory signalMODERATE.
Confidence levels per Intelligence Community Directive 203 (ICD 203) · Numbered links cite supporting reporting.
Activity domains (24h)
Total vs. priority (critical + high) reporting per domain.
- Cyber ActivitySalt Typhoon breach of US telecom carriers expands — lawful-intercept systems compromised
- DiplomacyXi to host Putin for state visit; joint declaration on 'no-limits' partnership 2.0
- PLA / MilitaryChina Coast Guard water-cannons Philippine resupply mission to Second Thomas Shoal
- Party & PowerPolitburo signals shift toward 'high-quality productive forces' as core 2026 economic doctrine
- Human RightsUN OHCHR briefing flags renewed forced-labor concerns in Xinjiang polysilicon supply chain
- State CouncilHong Kong LegCo passes Article 23 amendments expanding 'state secrets' definition
- Major EventsPudong New Area lockdown lifted after 36-hour COVID-style closure for 'epidemic drill'
Wednesday, September 16, 2026
Today's major events
All strategic- 1CN·critical20712d ago
Salt Typhoon breach of US telecom carriers expands — lawful-intercept systems compromised
WSJ / FBI - 2CN·critical20713d ago
CISA & NSA attribute new wave of Volt Typhoon intrusions to US critical infrastructure
CISA - 3SCS·high20712d ago
China Coast Guard water-cannons Philippine resupply mission to Second Thomas Shoal
PCG / Reuters - 4
- 5XZ·high20713d ago
Citizen Lab links new Android spyware sample to Tibetan diaspora monitoring campaign
Citizen Lab - 6
Priority tempo
Critical & high-severity events over the last 48h, bucketed by 2h.
PRC event timeline
14d · 0 eventsPeople's Republic of China regional heat map
Bubble size = report volume · color = severity mix · includes Taiwan & South China Sea
- Hot zone— Critical share > 25%
- High— Critical share > 10%
- Active— More than 8 total reports
- Steady— More than 3 reports
- Quiet— Low volume
Bubble radius scales with √(total reports) per region.
Critical alerts
Highest-severity events across all levels
CISA & NSA attribute new wave of Volt Typhoon intrusions to US critical infrastructure
Politburo signals shift toward 'high-quality productive forces' as core 2026 economic doctrine
Wang YiBio tours Gulf — strategic dialogue with Saudi Arabia, UAE focuses on yuan oil settlement
PBOC holds 1Y LPR at 3.10% — signals patience as deflationary pressure persists
PLA Eastern Theater Command conducts 4-day joint exercise around Taiwan
China Coast Guard water-cannons Philippine resupply mission to Second Thomas Shoal
CISA & NSA attribute new wave of Volt Typhoon intrusions to US critical infrastructure
UN OHCHR briefing flags renewed forced-labor concerns in Xinjiang polysilicon supply chain
Xi to host Putin for state visit; joint declaration on 'no-limits' partnership 2.0
Salt Typhoon breach of US telecom carriers expands — lawful-intercept systems compromised
PLAN Type-055 cruiser tracked 24nm off Yonaguni
Pudong New Area lockdown lifted after 36-hour COVID-style closure for 'epidemic drill'
District Council 'patriots-only' by-election sees record-low 27% turnout
Browse by domain
Drill into dated, sourced PRC cyber chronologies
Dated sourced events
Named public reporting, each entry cited
- Jul 9, 2026highoperationalGovernment and Diplomatic Espionage
Suspected China-nexus implants in Pakistani law enforcement web applications
SentinelLABS tracked sustained espionage against Pakistani law enforcement from February 2024 to April 2026. A suspected China-nexus actor planted implants in a Balochistan Police web application handling criminal and biometric records, reaching both police staff and citizens.
Suspected China-nexus actorSentinelLABS - Apr 23, 2026criticalstrategicEdge Devices and Covert Networks
Joint advisory on China-nexus covert networks of compromised devices
CISA and partners published tactics, techniques and indicators for covert networks built from compromised SOHO routers, IoT and smart devices. The advisory describes large-scale botnet infrastructure used to obscure attribution and enable reconnaissance and intrusion.
Volt TyphoonFlax TyphoonCISA AA26-113A - Aug 27, 2025criticalstrategicTelecommunications Collection
Countering PRC state-sponsored compromise of networks worldwide
NSA, CISA, FBI and partners detailed a deliberate and sustained campaign by PRC state-sponsored actors compromising networks worldwide to feed a global espionage system.
PRC state-sponsored APT actorsCISA AA25-239A - Dec 18, 2024highoperationalTelecommunications Collection
Mobile communications guidance issued after telecom espionage
CISA released mobile communications best practice guidance in direct response to identified PRC-affiliated espionage against commercial telecommunications infrastructure.
PRC government-affiliated actorsCISA guidance - Dec 4, 2024criticaloperationalTelecommunications Collection
Hardening guidance after PRC compromise of major carriers
CISA and partners warned that PRC-affiliated actors compromised networks of major global telecommunications providers in a broad cyber espionage campaign, and published visibility and hardening guidance for communications infrastructure.
PRC-affiliated threat actorsCISA guidance
Browse by country
Drill into per-country feeds