π΅οΈ RESEARCH & DEEP DIVES
-
T-Mobile Cut a Network Cable to Expel Salt Typhoon Hackers
T-Mobile physically severed a network cable to eject Salt Typhoon hackers in 2024.- T-Mobile and other U.S. telecom providers were targeted in the Salt Typhoon espionage campaign.
- The attackers sought phone records, communications metadata, and lawful-intercept systems.
- Salt Typhoon reached T-Mobile through a router belonging to another telecom company.
- T-Mobile detected anomalous traffic after months of searching and traced it to the compromised system.
- Four T-Mobile security staffers cut the systemβs external network cable at a Bellevue, Washington, data center.
π Coverage: techcrunch.com Β· π via Cyber Security News
-
Post-training cuts excess authority in terminal and MCP agents
Researchers trained an LLM agent to reduce unnecessary authority in terminal and MCP tasks.- Tool-using LLM agents operating in executable terminal and Model Context Protocol environments are affected.
- A 4B-parameter Qwen3.5-4B model was trained to avoid excess-authority actions beyond task requirements.
- The framework audits each action before execution and its observed effects across six risk dimensions.
- Across 2,896 evaluation episodes, safe success rose to 98.48% from 64.36%, while excess-authority errors fell to 0.79% from 4.56%.
π Coverage: arxiv.org Β· π via arXiv cs.CR
-
AUTOSIGMA automates Sigma rule generation from threat intelligence
Researchers introduced AUTOSIGMA for automatically converting CTI reports into Sigma detection rules.- Security teams using Sigma and SIEM platforms are the target users.
- AUTOSIGMA converts unstructured CTI reports into context-aware Sigma rules.
- It enriches inputs with a structured knowledge base and matches them to existing Sigma rule templates.
- An LLM-as-a-Judge iteratively validates the generated rules.
- Evaluations on APT reports and security blogs found stronger validity, relevance, ATT&CK coverage, and input robustness than alternatives.
π Source: arxiv.org Β· π Coverage: youtu.be Β· π via arXiv cs.CR
-
Researcher proposes multi-agent cyber defense architecture for connected vehicles
A researcher has proposed a three-tier multi-agent architecture for V2X security.- The proposal targets connected vehicles receiving V2X Basic Safety Messages.
- Fabricated emergency-braking alerts could reach vehicle planning systems and trigger unsafe braking.
- Onboard agents classify messages as Accept, Drop, Quarantine, or Escalate within 10 milliseconds.
- Roadside agents analyze fleet-wide signals within 50 milliseconds, while cloud agents update models through Byzantine fault-tolerant federated learning.
π Coverage: arxiv.org Β· π via arXiv cs.CR
-
Detecting DCSync Attacks Through Directory Replication Event Logs
DCSync attacks can be detected through Active Directory directory replication event logs.- Active Directory operators and defenders are affected.
- DCSync abuses directory replication to perform identity attacks.
- Attackers need replication permissions to use legitimate directory replication interfaces.
- The technique does not require malware on the domain controller.
π Source: clearpathsecurity.co.uk Β· π Coverage: securityboulevard.com Β· π via securityboulevard.com (discovered)
π ADVISORIES
- π Source for Splunk MCP Server App flaw enables RCE for admin users β advisory.splunk.com