China has reportedly instructed domestic organizations to stop using cybersecurity software from multiple U.S. and Israeli vendors, citing national security concerns that such tools could collect sensitive data and transmit it abroad. The directive, reported by Reuters and echoed in follow-on coverage, appears consistent with Beijing’s broader technology decoupling efforts and long-running policy initiatives to replace foreign technology in critical environments with domestic alternatives.
Named vendors affected include VMware (Broadcom), Palo Alto Networks, Fortinet, and Israel-based Check Point, with additional reporting listing a wider set of impacted security suppliers such as Mandiant, CrowdStrike, SentinelOne, McAfee, Recorded Future, Claroty, Rapid7, and Wiz, as well as Israeli firms CyberArk, Orca Security, Cato Networks, and Imperva (Thales-owned). Reporting indicates uncertainty about which Chinese entities received the notice and how broadly it applies, but notes the move had immediate market impact on affected companies’ stocks and aligns with China’s stated goal of reducing reliance on foreign software across state-linked sectors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Reuters and follow-on coverage on January 15, 2026 linked the software ban to China’s wider effort to replace Western technology with domestic alternatives, including policies such as Xinchuang and earlier foreign-software replacement directives. The reporting also noted market pressure on some affected vendors’ stock prices after the news became public.
Chinese authorities reportedly sent notices in recent days ordering domestic entities to stop using cybersecurity software from more than a dozen U.S. and Israeli vendors, citing national security concerns that the products could collect sensitive data and transmit it abroad. Reported affected companies include VMware, Palo Alto Networks, Fortinet, Mandiant, CrowdStrike, Check Point, and CyberArk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.