A new rule has been passed by the Chinese government, that claims that every cybersecurity experts have to report any kind of Zero-Day vulnerability they found in software within 2 days to the government.
However, the experts have no right to sell that information, without any prior consent of the government. The “Regulations on the Management of Network Product Security Vulnerabilities” have issued this new rule and it will be applicable from September 1, 2021.
According to the report, the new rules consist of some uncertain articles, well these new rules were issued by the Cyberspace Administration of China (CAC).
Here, we have mentioned some important articles, that is to be followed by the cybersecurity experts:-
Disclosing this vulnerability can lead to penalties, threatening law enforcement consequences through the Ministry of Public Safety.
Apart from this the Chairman of the Silverado Policy Accelerator, Dmitri Alperovitch explained the obligation to report all the details regarding the vulnerability to the MIIT within two days of the strike, and it is the most troubling part of the law.
The industries also have to follow these rules, and if they did not follow them then they have to face penalties. However, this new set of rules will be applicable from September 1st, 2021, as we said above.
The report claims that all these new sets of rules are part of a combined Beijing effort to sustain the country’s cybersecurity posture.
Apart from this, we all know that China has steadily hardened its authority over information and computer security over the past two decades, to circumvent any kind of risk.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Kali Linux users worldwide are facing an imminent disruption as the security-focused distribution has announced…
In a significant shift observed during the first quarter of 2025, cybersecurity experts have documented…
The cybersecurity landscape is witnessing a significant shift as threat actors increasingly leverage Ransomware as…
Senior members of the World Uyghur Congress (WUC) living in exile became targets of a…
A new Ransomware-as-a-Service (RaaS) group called RansomHub emerged in the cybercriminal ecosystem, specializing in targeting…
SAP released an emergency out-of-band patch addressing CVE-2025-31324, a critical zero-day vulnerability in SAP NetWeaver…