View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

T-Mobile Cut a Network Cable to Expel Salt Typhoon Hackers

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • T-Mobile Cut a Network Cable to Expel Salt Typhoon Hackers
    T-Mobile physically severed a network cable to eject Salt Typhoon hackers in 2024.

    • T-Mobile and other U.S. telecom providers were targeted in the Salt Typhoon espionage campaign.
    • The attackers sought phone records, communications metadata, and lawful-intercept systems.
    • Salt Typhoon reached T-Mobile through a router belonging to another telecom company.
    • T-Mobile detected anomalous traffic after months of searching and traced it to the compromised system.
    • Four T-Mobile security staffers cut the system’s external network cable at a Bellevue, Washington, data center.
      πŸ“Ž Coverage: techcrunch.com Β· πŸ‘ via Cyber Security News
  • Post-training cuts excess authority in terminal and MCP agents
    Researchers trained an LLM agent to reduce unnecessary authority in terminal and MCP tasks.

    • Tool-using LLM agents operating in executable terminal and Model Context Protocol environments are affected.
    • A 4B-parameter Qwen3.5-4B model was trained to avoid excess-authority actions beyond task requirements.
    • The framework audits each action before execution and its observed effects across six risk dimensions.
    • Across 2,896 evaluation episodes, safe success rose to 98.48% from 64.36%, while excess-authority errors fell to 0.79% from 4.56%.
      πŸ“Ž Coverage: arxiv.org Β· πŸ‘ via arXiv cs.CR
  • AUTOSIGMA automates Sigma rule generation from threat intelligence
    Researchers introduced AUTOSIGMA for automatically converting CTI reports into Sigma detection rules.

    • Security teams using Sigma and SIEM platforms are the target users.
    • AUTOSIGMA converts unstructured CTI reports into context-aware Sigma rules.
    • It enriches inputs with a structured knowledge base and matches them to existing Sigma rule templates.
    • An LLM-as-a-Judge iteratively validates the generated rules.
    • Evaluations on APT reports and security blogs found stronger validity, relevance, ATT&CK coverage, and input robustness than alternatives.
      πŸ“„ Source: arxiv.org Β· πŸ“Ž Coverage: youtu.be Β· πŸ‘ via arXiv cs.CR
  • Researcher proposes multi-agent cyber defense architecture for connected vehicles
    A researcher has proposed a three-tier multi-agent architecture for V2X security.

    • The proposal targets connected vehicles receiving V2X Basic Safety Messages.
    • Fabricated emergency-braking alerts could reach vehicle planning systems and trigger unsafe braking.
    • Onboard agents classify messages as Accept, Drop, Quarantine, or Escalate within 10 milliseconds.
    • Roadside agents analyze fleet-wide signals within 50 milliseconds, while cloud agents update models through Byzantine fault-tolerant federated learning.
      πŸ“Ž Coverage: arxiv.org Β· πŸ‘ via arXiv cs.CR
  • Detecting DCSync Attacks Through Directory Replication Event Logs
    DCSync attacks can be detected through Active Directory directory replication event logs.

    • Active Directory operators and defenders are affected.
    • DCSync abuses directory replication to perform identity attacks.
    • Attackers need replication permissions to use legitimate directory replication interfaces.
    • The technique does not require malware on the domain controller.
      πŸ“„ Source: clearpathsecurity.co.uk Β· πŸ“Ž Coverage: securityboulevard.com Β· πŸ‘ via securityboulevard.com (discovered)

πŸ“‹ ADVISORIES

  • πŸ“„ Source for Splunk MCP Server App flaw enables RCE for admin users β€” advisory.splunk.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check