Everyone is talking about the Bloomberg Businessweek’s volatile report alleging that Chinese spies had implanted surveillance chips in the motherboards of computer servers.
The report is not standing up to the smell test. As president Trump would say – This is fake news.
Apple, Amazon, and the other involved parties delivered strong denials. If these companies saw any potential truth in the article they would have not issued such strong denials. For one thing – if there was any truth in the article then each of these companies would have a high liability for misleading the public with the denials.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
It appears somewhat strange that nobody has reported identifying one of the spy chips from any motherboards in production. Would not it have been simple for any businesses using servers comprising elements from Supermicro, the firm whose products were supposedly backdoored, to send an engineer to find the miniature spy chip at one of their datacenters? I know engineers who work on circuit boards and these folks would easily be able to identify a maliciously installed component.
The Bloomberg article even showed a picture of the chip. I am sure that that image was just to enhance the impact of the story.
While lack of proof Isn’t enough to Debunk the report, it will raise doubts.
Joe Fitzpatrick, a hardware hacking pro and one of those sole named sources, stated that he finds out the story implausible.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the developments, risk shifts, and new signals that changed the picture after this article was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
The writers have published incorrect cybersecurity reports before. (nobody is ideal, but these previous crimes do raise an eyebrow) Even Rob Joyce, a leading National Security Agency official, stated he’s not discovered “any ties into the claims which are in this report.” He added:”I fear that we are chasing shadows at this time.”
The good thing about the article is that it has raised security consciousness related to supply chain management. There is more visibility on this issue. Likely this alone will make manufacturers take another look at vulnerabilities related to hardware security.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Coder’s registry infrastructure compromised to push malicious modules
The Coder incident is a supply-chain lesson in miniature: once attackers can tamper with trusted module distribution, defenders are no longer verifying...
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
The useful lesson in this campaign is not that Node.js is bad. It is that adversaries keep choosing legitimate runtimes defenders already...
HPE patches critical ArubaOS-CX remote code execution flaw
ArubaOS-CX deserves attention because switching software rarely gets treated with the same urgency as identity or edge security until exploitation arrives. A...
The 5-Minute Cyber Brief: September 4, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.