Two intelligence services from opposing states broke into the same police force, and neither one ever noticed the other was already there.
That’s the real story buried in SentinelOne’s latest threat roundup: state-linked hackers tied to both China and India have been rummaging around the Balochistan Police network in Pakistan for at least two years, tripping over each other in the dark the whole time. It’s not a flattering story about how good these operators are at espionage. It’s a grim one about how bad the target’s cybersecurity actually was, and how ordinary that blind spot is everywhere else, including your own network.

Two rival spy agencies, one dead alarm
Think about what it actually takes for this to happen. Two separate, well-funded threat actors, with no coordination and opposing interests, each get a foothold. Each sets up persistence. Each moves laterally, exfiltrates data, and comes back for more. And the defenders on the other end catch none of it, for years, from either side.
That’s not a story about sophisticated tradecraft. It’s a story about a network with no meaningful threat detection at all. When intrusion sets from rival nations can coexist undetected for that long, alert fatigue and missing telemetry aren’t the problem anymore. There’s no telemetry to be fatigued by.
Law enforcement networks make tempting targets precisely because they sit on identity records, informant data, and ongoing investigations. But the lesson generalizes past police departments. If your logging, EDR, and network monitoring can’t tell you when one attacker walks in, they definitely can’t tell you when two do. Defense in depth only works if every layer is actually watching.
Even your cybersecurity tools have bugs
Wireshark shipped version 4.6.7 this weekend, patching 12 vulnerabilities and 16 other bugs in the packet analyzer that half the incident response world reaches for first. That’s not a knock on the Wireshark team, who disclose and fix quickly and openly. It’s a reminder that the tools you use to do threat detection and incident response are themselves software, with their own attack surface, and they need the same patch discipline you’d demand of anything else on the network.
It’s easy to treat security tooling as exempt from the rules that apply to everything else. It isn’t. A vulnerable analysis tool sitting on an analyst’s workstation, parsing untrusted packet captures from a live investigation, is a genuinely dangerous place for a bug to live. Security hardening has to include the security stack itself, not just the systems it’s watching.
Patch the software that’s supposed to protect you
Zimbra is pushing an urgent update for its Classic Web Client after researchers found a stored cross-site scripting flaw serious enough to let a specially crafted email run code inside a logged-in user’s session. No CVE number yet, but the advisory is blunt: attacker-controlled email content, executing in your webmail session, with whatever access that session has. That’s a direct line from “I opened a message” to account takeover, no attachment or click required beyond viewing it.

Put the three stories together and the pattern is obvious. The network monitoring your incident response depends on can go blind for years. The analysis tools your team trusts can carry their own vulnerabilities. The webmail client your whole organization lives in can turn a single email into a session hijack. None of this requires exotic tradecraft. It just requires nobody checking.
None of these gaps are exotic. All of them are fixable with unglamorous, repeatable work.
- Patch Zimbra’s Classic Web Client now if you run it, and treat any unusual session activity in webmail as worth investigating immediately, not next sprint.
- Update Wireshark and any other analysis or forensic tooling on incident response workstations; don’t assume defensive software gets a pass on patch cycles.
- Audit whether your logging actually covers lateral movement and long-dwell persistence, not just perimeter alerts and brute-force login attempts.
- Segment high-value networks like law enforcement, HR, and finance systems so one compromised account can’t wander the whole environment.
- Pair firewall and threat-protection rules with actual log review; a rule nobody reads the output of isn’t a control, it’s a checkbox.
- Run tabletop exercises assuming an intruder has already been inside for months, since that’s the scenario that keeps showing up in the real incidents.
Cybersecurity budgets tend to chase the newest threat, the newest tool, the newest acronym. The Balochistan case argues for spending that money on the boring stuff instead: visibility into what’s already on your network, patch cadence for the tools defenders use, and incident response plans built for attackers who’ve been there longer than you think.
Sources
- China, India-Linked Hackers Both Targeted Same Pakistani Police Force
- The Good, the Bad and the Ugly in Cybersecurity – Week 28
- Wireshark 4.6.7 Released
- Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
