Chinese MSS-linked hacking group APT10 penetrated managed IT service providers globally, using them as conduits to exfiltrate data from at least 45 companies and government agencies across 12 countries.