decrypted · 6 october 2026 · vulnerabilities and patching · supply chain · uk policy and law

MI5 names a Chinese front that paid for UK academic research

The most interesting security warning this week did not come from a vendor. On 30 September MI5 told UK universities that a Chinese body, the China General Technology Research Institute (CGTRI), exists mainly to pay for research that strengthens Chinese state espionage. More than 100 UK-linked academics, MI5 says, contributed to projects it funded. No malware was involved. The attack surface was a grant letter.

How the money did the work

CGTRI is also known as the China Academy of General Technology. MI5 assesses it as a front for China's Ministry of State Security, and says the topics it funds include artificial intelligence, cybersecurity, covert communications systems and steganography, the art of hiding messages inside innocent-looking files. Some researchers, MI5 says, may not know who is really paying.

Think of a tin on a supermarket shelf. It looks like every other tin, but the thing you needed to know was which factory filled it. Here the product is research, the shelf is an academic collaboration and the factory is the paymaster. Everyone in the chain behaves reasonably, because each handoff looks routine. Only the origin matters, and the origin is the one thing nobody checked.

What changed in law

The alert points to sections 3 and 17 of the National Security Act 2023, which cover assisting a foreign intelligence service and accepting material benefits from one. Reporting says anyone who keeps taking CGTRI grants or working with it now risks prosecution. Security Minister Dan Jarvis said the alert exposes attempts by Chinese intelligence to covertly benefit from the expertise and research of UK academics. The Chinese embassy dismissed the claims as fabricated and malicious slander, and readers can weigh that denial accordingly.

The practical shift is knowledge. Before 30 September, an institution could plausibly say it did not know. After a public naming, that defence gets much thinner.

Not only a university problem

Any UK company with research partnerships, joint ventures, sponsored PhDs or contract R&D in AI, security or communications has the same blind spot: it can see the counterparty but not the funder. MI5 advised institutions to review current and planned CGTRI collaborations, trace funding sources for Chinese research partnerships, and use the Research Collaboration Advice Team and National Protective Security Authority guidance.

Three questions worth asking this week:

The Secure by Design lesson

Secure by Design means building so that the safe path is the default. The same idea applies to partnerships. A control that depends on each academic or project lead spotting a front company relies on luck. The design fix is dull: funding provenance as a mandatory field before a project starts, a named owner, and a hard stop when ownership cannot be traced. It costs an administrator's time and a few awkward conversations. Set against a criminal investigation, or against handing a hostile service your AI and cryptography work, that is cheap. Opinion, not advice: ask the awkward question before the grant is signed, not after the headline.

Also this week

NetScaler, a third problem in recent weeks. Citrix has published an advisory for CVE-2026-88779, scored 8.7. It is a memory overflow that can take services down, and repeated triggering may keep them down, though Citrix says it found no risk to customer data integrity. It only affects deployments configured as SAML service providers or identity providers, and is fixed in versions 14.1-73.41 and 13.1-64.28. CISA has added it to its exploited list and set a federal deadline of 7 October. watchTowr's Benjamin Harris suggested attackers may be knocking systems over to help exploit two earlier flaws, CVE-2026-88771 and CVE-2026-88772, which is a theory, not a confirmed finding. Patch, then check for compromise.

Apple wants AI agents kept off your disk. Apple has said it will introduce stricter controls on macOS Full Disk Access, which can expose files, mail, messages and browsing history, because AI agents are becoming more autonomous and the risks grow substantially. The announcement followed complaints that Meta's Muse agent had accessed a journalist's private iMessages; Meta says the access was opt-in. Apple has given no timetable. The lesson for UK firms is plain: an AI agent with blanket disk access is a data protection question, so know which staff have granted it.

Nikkei and the cloud front door. Nikkei disclosed that a hijacked Microsoft 365 account was used on 30 September to send about 9,000 emails with malicious links, and that names and email addresses may have been exposed. Separately, a cloud service it uses was accessed without authorisation from late July, potentially exposing 1,646 employees and business partners. Neither is attributed. Phishing-resistant sign-in and alerts on unusual mail volume are the design answers for any UK firm on Microsoft 365 or Google Workspace.

Sources

If you want help checking who really sits behind your suppliers and research partners, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.