The Royal United Services Institute (RUSI) warned that fragmented European policies on technology suppliers leave critical infrastructure exposed to security and economic dependency risks, particularly from Chinese vendors such as Huawei and ZTE. Only 10 of 27 EU member states have fully implemented the voluntary EU Toolbox for 5G Security, and Germany and Spain retain substantial Chinese equipment in their 5G radio-access networks. RUSI said Chinese legal requirements enabling state access to company data and vulnerability information could give intelligence services privileged early access to exploitable flaws.
RUSI urged the EU to establish a harmonized, clearly defined framework for assessing high-risk vendors while preserving national-security autonomy and accounting for sector-specific risks. Proposed Cybersecurity Act amendments would identify untrusted vendors across 18 critical sectors and could require operators to remove their equipment within 36 months. The institute called for security-led procurement, but cautioned that blanket country or vendor bans do not eliminate product vulnerabilities and that dependency and surveillance risks can also apply to US suppliers.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
Salt Typhoon compromised US telecommunications networks. RUSI cited the attacks as evidence that networks using non-Chinese technology can also be vulnerable.
The EU introduced its voluntary 5G Security Toolbox to harmonize mitigation of 5G security risks across member states.
China threatened Germany with economic consequences during its debate over 5G suppliers. RUSI later cited the episode as an example of Beijing using technological and economic influence.
RUSI published a report calling for a bloc-wide vendor-risk assessment framework that preserves national-security authority and accounts for sector-specific risks, noting that only 10 of 27 member states had fully implemented the 5G Security Toolbox. It warned about Chinese government control, data access and privileged access to vulnerability reports, while cautioning that blanket vendor bans do not resolve underlying product-security weaknesses.
The European Commission proposed Cybersecurity Act amendments enabling designation of untrusted vendors for exclusion from networks in 18 critical sectors, with equipment replacement required within 36 months. It indicated that Huawei and ZTE would be proposed for the potential list if the amendments passed.
Spain awarded Huawei a contract involving storage of judicial wiretap recordings, intensifying debate over the company's role in the country.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.