❌

Normal view

There are new articles available, click to refresh the page.
Today — 25 September 2026Main stream

Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks

24 September 2026 at 10:00

Two Senate committee leaders are introducing legislation to foster cybersecurity standards for the telecommunications sector nearly two years after the landmark Salt Typhoon campaign was made public.

First reported by CyberScoop, Virginia Sen. Mark Warner, the top Democrat on the Intelligence Committee, and Texas Sen. Ted Cruz, the GOP chairman of the Commerce, Science and Technology panel, are introducing the Telecommunications Cybersecurity and Resilience Act.

“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient. This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day.”

Federal officials have repeatedly warned that Salt Typhoon — the Chinese group blamed for the massive and “indiscriminate” espionage campaign that hit major telecom carriers and siphoned data from presidential campaigns and candidates — remains a threat to this day.

Yet some cyber officials have worried that public apathy over the attacks has stifled momentum for telecom security rules. In one case the Trump administration has rolled them back.

The Warner-Cruz legislation takes the approach of trying to improve telecom security with voluntary measures jointly developed by government and industry.

“Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” Cruz said. “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.”

Their bill would create a telecom cybersecurity working group within the National Telecommunications and Information Administration to bring together carriers, suppliers, experts and relevant government agencies. 

The working group would develop voluntary industry-wide best practices within 18 months of passage of the bill, which would be reviewed for updates every two years or after major incidents.

The best practices would “focus solely on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities,” according to the legislation, and would be in line with existing federal cybersecurity risk management frameworks.

The working group would also create a voluntary certification process through independent third-party assessors that companies could choose to use.

“What is missing” now, according to a summary of the bill, “is a common, telecom sector-specific set of best practices that brings that expertise together and can evolve as threats and technology change. Building on industry’s familiarity with security development and threat information sharing, this bill would bring stakeholders — government and private sector — together to develop and maintain effective techniques and practices to secure networks.”

The post Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks appeared first on CyberScoop.

Before yesterdayMain stream

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

By: djohnson
2 September 2026 at 13:57

The Federal Communications Commission wants to set up a new scorecard system that would allow rate telecoms’ ability to prevent or deter unwanted robocalls.

According to the agency, the scorecard “will empower consumers and encourage providers to continue to combat illegal robocalls by providing the public with an assessment of the effectiveness of voice service providers’ efforts to protect consumers from illegal robocalls,” the FCC said in a Wednesday public notice.

The notice does not prescribe or define technical solutions or systems for the scorecard, instead laying out broad goals for the project. Those include creating a public guide for evaluating how well providers prevent robocalls, and how transparent they are with their metrics.

The agency expressed a desire for more than “a simple administrative checklist,” such as whether the provider offered the right tools or filed the right paperwork, but rather “a composite set of metrics that reflects both operational practices and measurable outcomes, including how often legitimate calls are blocked.”

The scorecard would apply only to domestic voice service providers with retail customers, including wireless, wireline, VoIP providers and hybrid networks, but the agency is seeking comment from the public on whether to focus on larger providers, exclude small or regional networks and other questions around who would be evaluated.

The FCC says it intends to publish the scorecard results, but characterized it as a tool to help consumers understand how effectively voice service providers address robocalls on their networks and “not a rulemaking that will result in new rules or requirements for voice service providers.”

However, the notice does flag a number of federal data systems built around enforcement that the agency said it believes would be “best” for evaluating companies, including Robocall Mitigation Database filings, FCC Consumer Complaints Center data, and FCC enforcement action data, along with third-party or industry sources like Industry Traceback Group data and Federal Trade Commission complaint data.

Peter Hyun, former acting head of enforcement at the FCC, endorsed the general concept behind the idea, likening it to the Department of Transportation’s creation of an airline customer service dashboard in 2024.

That transparency “helped foster adoption of improved practices and a strong focus on better outcomes for consumers,” Hyun told CyberScoop in a text message. “With recent legal and policy fights over FCC enforcement, this is a creative effort to use other tools to combat what is an ever-tormenting issue for consumers: illegal calls.”

FCC officials have emphasized that the most frequent complaints they hear from consumers are around robocalling, and they are seeking to address that demand in a variety of ways.

On the same day the scorecard was unveiled, the FCC announced it had booted 14 telecommunications providers from the Robocall Mitigation Database. The federal system is used by companies to document their compliance with anti-robocalling standards — like STIR/SHAKEN protocols — that FCC officials say are vital to helping them validate legitimate network traffic moving through the U.S. and identify bad actors.

Removing a company from the database effectively cuts it off from connecting to U.S. telecom networks. FCC regulations give other U.S. providers two days to block all traffic coming from violators.

“Today’s action pushes more than a dozen providers off of U.S. networks for failing to abide by our robocall rules,” said FCC Chair Brendan Carr. “The FCC continues to attack the problem of illegal robocalls at every point along the call path, and everyone in this ecosystem has an obligation to step up and do what they can to protect consumers against fraud and scammers.”

According to the FCC, the 14 companies failed to respond to take necessary steps when informed that their database certifications were out of compliance. The list of affected companies includes Apps Communications, CFX Business Solutions, Conference America, Convergence Technology Solutions, CSB Technologies, Digital Division, Dixie Net Communications, HighComm, Inatech Solutions, makrodepot, Opex Communications, ReachME, SECURE, and SkyCom Healthcare.

The post FCC proposes public scorecard to rate telecoms on anti-robocall efforts appeared first on CyberScoop.

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

26 August 2026 at 14:47

Ubiquiti has patched 21 critical vulnerabilities, three of which were rated the highest severity possible, the communications product company said Wednesday in a security bulletin.

In all, the company patched 22 vulnerabilities, with the last one rated “high,” it said in the bulletin.

Three of the vulnerabilities had a Common Vulnerability Scoring System rating of 10 out of 10. Each of them would allow a hacker to access privileges on the device or application.

All but one of the 22 vulnerabilities affect the UniFi line of products. The three maximum-security vulnerabilities are CVE-2026-77537, CVE-2026-77550 and CVE-2026-77554.

In all three, hackers could exploit an improper access control vulnerability, the same kind in seven of the total vulnerabilities Ubiquiti disclosed Wednesday. Other vulnerabilities would allow hackers to do things like bypass authentication or run arbitrary commands.

Ubiquiti, which claimed revenues of $2.57 billion last year, released the bulletin without commentary, besides identifying the vulnerabilities and recommended mitigations. The company did not immediately respond to a request for comment about whether it had seen any of the exploits used in the wild before they were patched.

The trio of maximum-security vulnerabilities patched equals the total the company had disclosed this year before Wednesday.

In March, the company disclosed that it had patched a single maximum-security vulnerability. It disclosed one more in both May and July of this year.

Two months ago, the Cybersecurity and Infrastructure Security Agency added three Ubiquiti vulnerabilities to its list of flaws that were known to have been exploited, sometimes called the agency’s “must-patch” list.

The post Three 10.0 security flaws fixed across Ubiquiti’s UniFi line appeared first on CyberScoop.

❌
❌