home.social

#salttyphoon — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #salttyphoon, aggregated by home.social.

  1. Salt Typhoon nella PA italiana: Sistemi Informativi di IBM violata per due settimane, il cyberspionaggio cinese entra nella supply chain dello Stato

    Il gruppo APT cinese Salt Typhoon ha compromesso Sistemi Informativi, la controllata IBM che gestisce l'infrastruttura IT di ministeri, INPS, INAIL e banche italiane. Un'intrusione silenziosa durata circa due settimane, individuata a inizio maggio 2026: il caso più significativo di cyberspionaggio sulla supply chain digitale italiana dalla promulgazione della NIS2.

    insicurezzadigitale.com/salt-t

  2. #FCC bans import of consumer #routers not made in #US over security threat — agency says foreign-made devices pose ‘unacceptable risk’ to US persons
    Blamed foreign-made routers for Volt, Flax, and #SaltTyphoon #cyberattacks that hit critical American infrastructure, “routers in the #UnitedStates must have trusted supply chains so we are not providing foreign actors with a built-in backdoor to American homes, businesses, #criticalinfrastructure, and emergency services.” tomshardware.com/networking/ro

  3. @as400 @khalid @postmarketOS I'm daily driving a #Librem5 with #postmarketOS and I've tested reliable voice calling successfully with multiple carriers in two counties. Also, tested with #PureOS.

    Owners of older units may need to upgrade modem firmware and enable VoLTE manually. The real problem in my limited knowledge is carriers are blocking devices which are not on their 'approved list' or which they think are not VoLTE capable.

    Another, bigger questions is: why are people still using unencrypted legacy voice calls for personal communications in 2026?

    #SaltTyphoon

  4. Senator says #ATT , #Verizon blocking release of #SaltTyphoon #security assessment reports-Reuters

    Dem Sen #Cantwell said Verizon & AT&T are blocking release of key docs about an alleged massive #Chinese #spying operation that infiltrated US #telecom networks known as Salt Typhoon & wants their CEOs to appear before Congress to answer questions

    Cantwell asked both companies to turn over security assessments conducted by Alphabet #cybersecurity unit #Mandiant
    #privacy

    reuters.com/business/media-tel

  5. Two former Cisco Networking Academy students have been linked to the Salt Typhoon campaign, which has compromised 80+ global telecom providers. Investigators say the attackers used technical skills learned directly from Cisco’s curriculum to target IOS and ASA devices.

    This case reignites debate over whether corporate training programs in politically tense regions may inadvertently strengthen future threat actors.

    Source: cybersecuritynews.com/chinese-

    Curious how the community views this risk.
    Follow TechNadu for more verified cybersecurity reporting.

    #CyberSecurity #Infosec #CiscoSecurity #ThreatIntel #SaltTyphoon #TelecomSecurity #SecurityResearch

  6. @Sxan I'm not in the US, but #Librem5 works with carrier T-Mobile and Purism's Awesim according to their wiki and forums.

    I'm daily driving Librem 5 with #postmarketOS (stable - phosh) and everything critical for my use case works: VoLTE calls and SMS (although I avoid both now since #SaltTyphoon), 4G data, Wi-Fi, basic camera, GPS navigation using #PureMaps, latest apps from #Flathub, web browsing using Firefox-ESR, e2ee messaging and calling using Signal Desktop, DeltaChat, Matrix, XMPP, etc. and of course my most used feature, the headphone jack!

    What does not work is recording sound in videos, although recording sound itself using Sound Recorder works, just not in videos.

    Correctin: Recording sound in videos does work on L5 both on pmOS and PureOS.

  7. @ati1 @linmob Depends what the user wants from a personal device, how they use it and what their priorities are. If someone's priorities are a modern camera, running proprietary Android apps and their money is held hostage by banks requiring #Duopoly apps, they should check back later, perhaps when the Librem 5 "Fir" model is released.

    On the other hand, if #FreeSoftware, #privacy, #modularity, #repairability, #ecofriendliness, #decentralisation, #digitalindependence, etc. are valued above other things, the Librem 5 and the higher-spec model, the #LibertyPhone, can absolutely work in 2025 and beyond.

    I am daily driving a #Librem5 with #postmarketOS and everything important to me works: VoLTE calls and SMS (although I avoid them due to #SaltTyphoon), 4G data, Wi-Fi, camera with OK quality photos (see: #ShotOnLibrem5), GPS with #PureMaps, web browsing with #FirefoxESR, web apps (including banking) using #GNOMEWeb and #BraveBrowser, email using #Geary and #DeltaChat, audio calls on #SignalMessenger, #Matrix ( #ElementMessenger), #XMPP ( #DinoIM), #JitsiMeet, etc.

    There are occasional bugs and quirks, and the device itself has limitations but nothing that I can't work around.

    Not sure if I missed anything. Let me know if you have a specific use case that you absolutely require and I'll see if I can test...

  8. The# FBI confirmed that the #Chinese-backed #hacking campaign, #SaltTyphoon, hacked at least 200 US companies and 80 countries. The hackers targeted call records of senior #Americanpoliticians and officials, prompting the FBI to urge Americans to switch to #encryptedmessaging apps. techcrunch.com/2025/08/27/fbi- #tech #media #news

  9. Happy Wednesday everyone!

    News broke that #SaltTyphoon gained access to the U.S. National Guard's network "and, among other things, collected its network configuration and its data traffic with its counterparts’ networks in every other US state and at least four US territories, according to a DOD report. This data also included these networks’ administrator credentials and network diagrams—which could be used to facilitate follow-on Salt Typhoon hacks of these units."

    I am posting this as situational awareness and I never try to strike fear in the community, so I want to remind everyone of the great resources that exist out there when you want to threat hunt or you are trying to detect activity related to different #APT groups or malware! Check out the article posted below and check the comments for resources I would recommend using to supplement your threat hunting or blue team efforts! Enjoy and Happy Hunting!

    DHS Salt Typhoon
    documentcloud.org/documents/25

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  10. #Senators to #Noem: Axing review board puts 'lives at risk'
    A group of Democratic senators has urged #HomelandSecurity Secretary #KristiNoem to reestablish the Cyber Safety Review Board (#CSRB), which had been investigating how #China's #SaltTyphoon hacked US government and telecommunications networks.
    theregister.com/2025/06/02/sen

  11. #Senators to #Noem: Axing review board puts 'lives at risk'
    A group of Democratic senators has urged #HomelandSecurity Secretary #KristiNoem to reestablish the Cyber Safety Review Board (#CSRB), which had been investigating how #China's #SaltTyphoon hacked US government and telecommunications networks.
    theregister.com/2025/06/02/sen

  12. to : Axing review board puts 'lives at risk'
    A group of Democratic senators has urged Secretary to reestablish the Cyber Safety Review Board (), which had been investigating how 's hacked US government and telecommunications networks.
    theregister.com/2025/06/02/sen

  13. #Senators to #Noem: Axing review board puts 'lives at risk'
    A group of Democratic senators has urged #HomelandSecurity Secretary #KristiNoem to reestablish the Cyber Safety Review Board (#CSRB), which had been investigating how #China's #SaltTyphoon hacked US government and telecommunications networks.
    theregister.com/2025/06/02/sen

  14. #Senators to #Noem: Axing review board puts 'lives at risk'
    A group of Democratic senators has urged #HomelandSecurity Secretary #KristiNoem to reestablish the Cyber Safety Review Board (#CSRB), which had been investigating how #China's #SaltTyphoon hacked US government and telecommunications networks.
    theregister.com/2025/06/02/sen

  15. With Chinese diplomats reportedly admitting to targeting US Critical Infrastructure as a "warning to the U.S. about Taiwan" and some in the industry war-gaming the possibility of Cyber Effects being used to sway the Trade dispute between the US and China, now seemed a good time to do a reality check on how - if at all - China would do so.

    The bottom line - expect a surge in cyber espionage and signaling campaigns targeting US telcos and leadership to provide the CCP a competitive advantage in negotiations and their backdoor dealings.🕵️

    Cyber Security doesn't operate in a vacuum - here's a good example of where geopolitics starts to seep in at the edges: opalsec.io/is-cyber-a-legitima

    #CyberSecurity #InfoSec #ThreatIntel #China #USChinaTradeWar #Geopolitics #CyberWarfare #CriticalInfrastructure #VoltTyphoon #SaltTyphoon #NationalSecurity #CyberThreats #RiskManagement #GeopoliticalRisk #CyberPolicy #CISA

  16. Brass Typhoon: The #Chinese #Hacking Group Lurking in the Shadows

    Though less well-known than groups like #VoltTyphoon and #SaltTyphoon , #BrassTyphoon , or #APT41 , is an infamous, longtime #espionage actor that foreshadowed recent telecom #hacks.
    #security #China

    wired.com/story/brass-typhoon-

  17. Hey #CyberSecurity pros! 👋 Ready to dive into the latest threats and breaches making headlines?

    Our latest blog post is packed with need-to-know info to keep you ahead of the curve.

    🗞️ opalsec.io/daily-news-update-t

    Here's a quick rundown of what's inside:

    🕵️‍♂️ FamousSparrow's Return: The Chinese government-backed hacking group is back, targeting organizations in North America. Important distinction: ESET insists on tracking them separately from Salt Typhoon. Remember to prioritize TTPs and IOCs/IOAs accordingly!

    🗄️ RedCurl's Ransomware Twist: This corporate espionage group is now deploying "QWCrypt" ransomware, targeting Hyper-V servers. Phishing emails with malicious IMG attachments are the initial attack vector.

    😬 StreamElements Data Breach: A third-party service provider suffered a breach, exposing data of 210,000 customers.!

    🏛️ NSW Court System Data Theft: Sensitive documents, including AVOs, were stolen from the NSW Online Registry website. This could have serious consequences for victims of domestic violence.

    👨‍🎓 NYU Website Defacement: A hacker compromised NYU's website, leaking personal data of over 1 million students. Even with good intentions, the collateral damage is unacceptable.

    💰 Defense Contractor Fined: MORSE Corp will pay millions for failing to meet federal cybersecurity requirements. Third-party risk management is crucial!

    🤖 Atlantis AIO Automates Credential Stuffing: This new platform automates credential stuffing attacks against 140 online services. Stay vigilant against brute force attacks!

    🚨 Chrome Zero-Day Exploited: Google patched a zero-day vulnerability exploited in espionage campaigns targeting Russian organizations. Keep your browsers updated!

    👦 UK Warns of 'Com Networks': The UK's NCA is warning of a growing threat from online networks of teenage boys who are "dedicated to inflicting harm and committing a range of criminality." A very worrying trend that we need to be aware of.

    Ready for the full scoop? Read the full blog post here 👉 opalsec.io/daily-news-update-t

    #Cybersecurity #InfoSec #DataBreach #Ransomware #ThreatIntelligence #DataPrivacy #ZeroDay #FamousSparrow #RedCurl #StreamElements #NSWCourts #NYU #MORSECorp #AtlantisAIO #Chrome #ComNetworks #SecurityNews #CybersecurityThreats #InfoSecurity #CyberAttack #DataSecurity #PrivacyMatters #Vulnerability #Cybercrime #ThreatActor #ESET #SaltTyphoon #NIST #ZeroTrust #SaltTyphoon #CriticalInfrastructure

  18. @kookie64 Everything (data, calls, text, voicemail) works for me except #MMS but that's not included in my plan anyway. However, it depends on your region and carrier as not everyone's experience has been as great as mine : )

    Also, my use case is not normal I think. I try to use only #Signal, #Matrix and #DeltaChat with family and friends and discourage people from contacting me on legacy unencrypted phone calls and #SMS by changing my phone number every year!

    Guess we need a #SaltTyphoon type incident in our country for people to get off SMS...?

  19. During confirmation hearings in the US Senate for the role of deputy director of the Dept of #HomelandSecurity, the nominee #TroyEdgar said #CISA has had the wrong management and needed to be "reined in."
    Cyber Safety Review Board (#CSRB) had been probing #China's #SaltTyphoon campaign, in which telecommunication networks in America and beyond had been compromised by Beijing to snoop on potentially millions of people, though now CISA has taken over that role, Edgar said.
    theregister.com/2025/02/26/dhs

  20. During confirmation hearings in the US Senate for the role of deputy director of the Dept of #HomelandSecurity, the nominee #TroyEdgar said #CISA has had the wrong management and needed to be "reined in."
    Cyber Safety Review Board (#CSRB) had been probing #China's #SaltTyphoon campaign, in which telecommunication networks in America and beyond had been compromised by Beijing to snoop on potentially millions of people, though now CISA has taken over that role, Edgar said.
    theregister.com/2025/02/26/dhs

  21. During confirmation hearings in the US Senate for the role of deputy director of the Dept of , the nominee said has had the wrong management and needed to be "reined in."
    Cyber Safety Review Board () had been probing 's campaign, in which telecommunication networks in America and beyond had been compromised by Beijing to snoop on potentially millions of people, though now CISA has taken over that role, Edgar said.
    theregister.com/2025/02/26/dhs

  22. During confirmation hearings in the US Senate for the role of deputy director of the Dept of #HomelandSecurity, the nominee #TroyEdgar said #CISA has had the wrong management and needed to be "reined in."
    Cyber Safety Review Board (#CSRB) had been probing #China's #SaltTyphoon campaign, in which telecommunication networks in America and beyond had been compromised by Beijing to snoop on potentially millions of people, though now CISA has taken over that role, Edgar said.
    theregister.com/2025/02/26/dhs

  23. During confirmation hearings in the US Senate for the role of deputy director of the Dept of #HomelandSecurity, the nominee #TroyEdgar said #CISA has had the wrong management and needed to be "reined in."
    Cyber Safety Review Board (#CSRB) had been probing #China's #SaltTyphoon campaign, in which telecommunication networks in America and beyond had been compromised by Beijing to snoop on potentially millions of people, though now CISA has taken over that role, Edgar said.
    theregister.com/2025/02/26/dhs

  24. How pray tell is this a good move??

    Department of Homeland Security (DHS) disbands all memberships of advisory committees including the Cyber Safety Review Board (CSRB). thehackernews.com/2025/01/trum #Hackers #CyberSecurity #cybercrime #DHS #CSRB #Log4j #SaltTyphoon #security

  25. How pray tell is this a good move??

    Department of Homeland Security (DHS) disbands all memberships of advisory committees including the Cyber Safety Review Board (CSRB). thehackernews.com/2025/01/trum #Hackers #CyberSecurity #cybercrime #DHS #CSRB #Log4j #SaltTyphoon #security

  26. How pray tell is this a good move??

    Department of Homeland Security (DHS) disbands all memberships of advisory committees including the Cyber Safety Review Board (CSRB). thehackernews.com/2025/01/trum #Hackers #CyberSecurity #cybercrime #DHS #CSRB #Log4j #SaltTyphoon #security

  27. How pray tell is this a good move??

    Department of Homeland Security (DHS) disbands all memberships of advisory committees including the Cyber Safety Review Board (CSRB). thehackernews.com/2025/01/trum

  28. The US Department of Homeland Security has dismissed all members of advisory committees, including the Cyber Safety Review Board. The board had been investigating the Salt Typhoon cyberattack on US telecoms infrastructure.

    computing.co.uk/news/2025/secu

    #technews #cybersecurity #csrb #salttyphoon

  29. The US Department of Homeland Security has dismissed all members of advisory committees, including the Cyber Safety Review Board. The board had been investigating the Salt Typhoon cyberattack on US telecoms infrastructure.

    computing.co.uk/news/2025/secu

    #technews #cybersecurity #csrb #salttyphoon

  30. The US Department of Homeland Security has dismissed all members of advisory committees, including the Cyber Safety Review Board. The board had been investigating the Salt Typhoon cyberattack on US telecoms infrastructure.

    computing.co.uk/news/2025/secu

    #technews #cybersecurity #csrb #salttyphoon

  31. The US Department of Homeland Security has dismissed all members of advisory committees, including the Cyber Safety Review Board. The board had been investigating the Salt Typhoon cyberattack on US telecoms infrastructure.

    computing.co.uk/news/2025/secu

    #technews #cybersecurity #csrb #salttyphoon

  32. The US Department of Homeland Security has dismissed all members of advisory committees, including the Cyber Safety Review Board. The board had been investigating the Salt Typhoon cyberattack on US telecoms infrastructure.

    computing.co.uk/news/2025/secu

    #technews #cybersecurity #csrb #salttyphoon

  33. Weekly output: Android 16, Mark Vena podcast, CISA communications-security advice

    I hope this finds you well and with family this holiday season, by which I mean I hope that family tech support has not been too strenuous whether you’re the provider or the recipient of it.

    Patreon readers got an extra post this week: a look at the massive dent that data centers will put into Virginia’s electric grid in coming decades if current trends continue.

    12/18/2024: Latest Android 16 Preview Tips Improved App Response, Location Security, PCMag

    This short post covered the second developer preview of Android 16, moving forward on an earlier development cycle than previous releases of Google’s mobile operating system.

    12/18/2024: Ep 105 SmartTechCheck Podcast — Expected CES Trends, Intel CEO departure, new incoming FCC leader, Mark Vena

    My major contribution to this episode of my tech-analyst pal’s podcast was trying to unpack the agenda of incoming Federal Communications Commission chair Brendan Carr.

    12/19/2024: The Feds Have Some Advice for ‘Highly Targeted’ Individuals: Don’t Use a VPN, PCMag

    I’ve been impressed for the past few years by how the Cybersecurity & Infrastructure Security Agency offers specific and actionable advice even if it may upset some vendors. CISA stuck to that pattern with the guidance it issued to people high enough in government or politics to draw the attention of Chinese state-sponsored hackers who have burrowed deeply into U.S. telecom infrastructure–guidance that included the seemingly counter-intuitive advice not to use a VPN for privacy protection because that only transfers the privacy risk from your current sources of connectivity to a single company. I think CISA’s right about that, certainly in the context of most PCMag readers. And in my own case: My major use case for VPNs these days is to evade geoblocking restrictions, like when I’m trying to read GDPR-incompliant U.S. news sites from somewhere in the EU.

    #Android16 #BrendanCarr #ChinaHacks #ChineseHacking #CISA #cybersecurity #encryptedMessaging #FCC #infosec #SaltTyphoon #VPN