Natto Thoughts

211 Followers
17 Following
135 Posts
Natto Thoughts explores the intersection of culture, technology and security, with stories, analysis and insights into the humans of the information age—whether decision-makers, criminals, or ordinary users.

RE: https://infosec.exchange/@cR0w/116336272151255693

Nice to see you again @cR0w. All that popcorn will last anyone a long time. We'd better put extra effort into making the "shows."

The latest Natto Thoughts report examines the challenges and potential cyber implication of a likely scenario of China-Taiwan conflict.

https://www.nattothoughts.com/p/wargaming-a-china-taiwan-conflict

Wargaming a China-Taiwan Conflict and Its Cyber Scenarios

China’s use of cyber strategies in a conflict with Taiwan is likely to follow a methodical, gradual approach

Natto Thoughts
Faux Amis: How France Stands Apart in Europe’s High-Risk University Cyber Partnerships with China

France hosts the EU’s densest cluster of cyber partnerships with Chinese defense-linked universities, raising exposure to dual-use knowledge transfer, EU funding access, and institutional influence

Natto Thoughts
Is China’s National Research Center for Information Technology Security a hidden arm of the PLA Cyberspace Force?
Under a “two signboards” model, the NITSC operates under a civilian façade while serving Party, government, and military needs.
In our latest report, the Natto Team examines how state-affiliated entities—beyond the private sector—support China’s cyber ambitions. We analyze NITSC’s structure, affiliations, and capabilities, and uncover its potential military ties.
Read more and explore the implications.
https://www.nattothoughts.com/p/chinas-national-research-center-for
China’s National Research Center for Information Technology Security: Is It Part of the PLA Cyberspace Force?

Under “Two signboards” arrangement, the NITSC offers services to public, Party, government, and military entities, under the guise of a civilian name.

Natto Thoughts
The Tianfu Cup Returns Under MPS Leadership as AI Takes Center Stage

After a two-year hiatus, the Tianfu Cup returns under MPS lead, combining AI-assisted vulnerability discovery and exploitation, a new competition track, and less transparency in vulnerability handling

Natto Thoughts
Provincial Tasking, Cross-Provincial Execution: A Case-Based Look at How China Scales Cyber Operations

How decentralized MSS and MPS tasking and market-enabled, cross-provincial execution by commercial firms shape the scale of China’s cyber operations

Natto Thoughts

Intense competition, rapid innovation, and deep state linkages define the overall trend of China’s cybersecurity industry in 2025. Our latest Natto Thoughts analysis looks at China’s 2025 Top 20 Cybersecurity Companies and asks a forward-looking question: which “dark horses” are poised to break out in 2026? Some of the strongest performers may not be the most famous names, but they are shaping the future of China’s cyber ecosystem in important ways.

https://nattothoughts.substack.com/p/chinas-2025-top-20-cybersecurity

China’s 2025 Top 20 Cybersecurity Companies: Which “Dark Horses” Will Emerge to Prominence in 2026?

Annual ranking reveals hyper-competitive, innovation-focused top performers – some familiar and some not so well known, with extensive government ties

Natto Thoughts

From attack–defense thinking to vulnerability research and exposed threat actors, the Natto Team explored key aspects of China’s cyber ecosystem in 2025.

https://nattothoughts.substack.com/p/a-look-back-at-the-top-5-natto-thoughts

A Look Back at the Top 5 Natto Thoughts Reports in 2025

From attack–defense thinking to vulnerability research and exposed threat actors, we explored key aspects of China’s cyber ecosystem

Natto Thoughts

RE: https://infosec.exchange/@cR0w/115730402278887126

Thank you for sharing your enthusiasm for Popcorn Time.

In this post, we assess that provincial bureaus of the Chinese Ministry of State Security likely conduct cyber operations with their own tasking priorities, resources, and local ecosystems.

The Natto Team examines the leaked incident from Knownsec’s perspective to explore the role that elite Chinese cybersecurity companies play in building the country’s cyber capabilities.

https://nattothoughts.substack.com/p/knownsec-the-king-of-vulnerability

Knownsec: The King of Vulnerability Missed Three Vulnerabilities of Its Own

The leak incident involving Chinese cybersecurity firm Knownsec shows the company’s seemingly transparent crisis management strategy and underscores its position in the industry, but mysteries remain.

Natto Thoughts