Hello Readers,
Saturday, September 12, 2026
The Takeaway
A simulated AI-powered attack on WeChat has exposed the vulnerability of a platform embedded in China’s payments, communications and government services—adding urgency to U.S.–China safety talks ahead of the expected September 24 Trump–Xi summit. Yet allegations of model theft and Huawei’s criminal trial show how difficult cooperation remains. Xi’s first India visit in seven years offers a parallel test of selective rapprochement, while Manila’s public confrontation with Beijing underscores persistent maritime tensions.
Headlines tell you what happened. Chinese-language sources help you understand how Beijing sees it.
Today’s briefing shows why that distinction matters—from AI security debates to Chinese analysts’ interpretations of Xi’s India visit.
Go deeper with the China OSINT Course and sharpen how you read China beyond the headlines.
At Terton Intelligence, we recently launched a new news tracking product: tertonintel.com/watch. The news feed updates every hour, and it’s free to all.
1. Mock WeChat attack exposes China’s AI security dilemma
The Big Picture: A small California security team demonstrated an AI-built tool that could potentially compromise millions of WeChat accounts within hours, according to the New York Times’ account of the simulated attack. The demonstration raises the stakes for protecting digital infrastructure as increasingly capable hacking tools become accessible to actors without government backing.
The Details:
The demonstration: Palo Alto security company Calif said it built WeWorm in a little over a week. The tool could hijack an account and propagate through calls to the user’s contacts without recipients answering. This was a demonstration of potential compromise, not a reported breach of millions of accounts.
The exposure: WeChat serves 1.4 billion monthly users. Its integration into messaging, payments, business and government services means a widespread disruption could affect essential daily transactions.
The disclosure: Calif said it notified Tencent, WeChat’s owner, and the White House. The company says it develops such tools to strengthen defenses rather than sell them.
Beijing’s response: Foreign Ministry spokesperson Mao Ning said she was unfamiliar with WeWorm when asked on Wednesday. Separately, China has issued guidelines governing AI agents and is developing more than a dozen cybersecurity standards, the Times reports.
The cooperation problem: Chinese firms must first report discovered vulnerabilities to the Ministry of Industry and Information Technology, complicating expectations of reciprocal disclosure to foreign companies.
The proposed safeguards: Chinese scholars have suggested voluntary lists of prohibited AI-enabled cyber activities and protected categories of critical infrastructure. Experts cited by the Times see crisis communication as a more plausible near-term outcome than restrictions on AI development itself.
Between the Lines: The same capabilities that help defenders discover weaknesses can help attackers exploit them. Better defensive models may therefore look threatening to the other side, encouraging an arms race even when both governments describe their investments as protective.
Why It Matters: WeWorm makes the safety debate concrete: a vulnerability in one widely used service could have national consequences. Incident notification, responsible disclosure and emergency communication are practical tests of whether Washington and Beijing can cooperate despite their rivalry.
2. Manila turns Beijing’s handwritten objection into a public confrontation
The Big Picture: Philippine Defense Secretary Gilberto Teodoro used an unsolicited note at the September 8 Seoul Defense Dialogue to challenge China’s rejection of the 2016 South China Sea arbitration award, bringing the dispute directly onto an international security stage.


