Georgia Tech researchers reported that the global threat intelligence (TI) data supply chain has systemic weaknesses that can be exploited or exacerbated by geopolitical pressure, potentially degrading defenders’ ability to detect and respond to threats. Their work, to be presented at the NDSS Symposium, frames the TI ecosystem as an interdependent network of TI platforms (e.g., VirusTotal, MalwareBazaar), antivirus vendors, and malware sandbox services, where inconsistent data quality, uneven participation, and concentrated “nexus” sharing relationships create bottlenecks and delays in intelligence propagation.
In experiments using benign but suspicious binaries shared with 30 security vendors, the researchers found that while many vendors performed sandboxing, far fewer shared resulting intelligence onward (reported as 67% conducting sandbox analysis vs 17% sharing derived TI), contributing to hours-to-days lag in dissemination and uneven coverage. The research also highlights risks from shallow analysis and shared research infrastructure that could aid adversary evasion, and it proposes a secure data provenance approach intended to improve trust and enable TI use regardless of origin country—while noting that the hardest problem is establishing legitimate transnational governance amid conflicting national mandates and rising tech-policy tensions (including reported moves that could restrict foreign security software over data-leakage concerns).

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
On publication of the research coverage, Georgia Tech researchers reported inconsistent data quality, limited sharing beyond IOCs, chokepoints created by a few nexus vendors, and delays of hours to days in threat intelligence dissemination. They also proposed a secure provenance system to improve trust and policy-compliant sharing across borders.
In research for a forthcoming NDSS Symposium paper, Georgia Tech researchers distributed benign but suspicious instrumented binaries to 30 security vendors to measure sandboxing, analysis depth, and how threat intelligence propagates across the ecosystem.
Georgia Tech researchers cite an apparent Chinese ban on certain US- and Israeli-made security software in January 2026 as evidence of growing geopolitical distrust over threat intelligence data leakage.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.