Sens. Mark Warner and Ted Cruz introduced the bipartisan Telecommunications Cybersecurity and Resilience Act following the Salt Typhoon espionage campaign against U.S. communications providers. The China-attributed operation compromised systems handling lawful-surveillance requests, targeted telecom companies and prominent political figures, and expanded globally; U.S. officials warn Beijing could retain stolen information indefinitely for future surveillance or exploitation.
The bill would require the National Telecommunications and Information Administration to convene carriers, suppliers, cybersecurity experts, and relevant agencies to develop voluntary, telecom-specific practices within 18 months, aligned to existing federal risk-management frameworks. The guidance would be reviewed every two years or after significant incidents, while independent third-party assessors would offer voluntary certifications of providers’ adoption rather than impose mandatory federal requirements.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Senators Mark Warner and Ted Cruz introduced the bipartisan Telecommunications Cybersecurity and Resilience Act in response to Salt Typhoon. The bill would establish an NTIA working group to develop voluntary telecom security practices and a voluntary independent third-party certification process.
Senator Maria Cantwell said AT&T and Verizon prevented Mandiant from conducting network-security assessments she had requested, and called for the companies' chief executives to testify.
The Federal Communications Commission reversed a Biden-era measure intended to prevent unauthorized access to systems handling lawful-surveillance requests. FCC Chairman Brendan Carr said the agency had misinterpreted its authority and cited carriers' voluntary security improvements.
The Salt Typhoon campaign targeting major U.S. telecommunications providers was publicly disclosed. The Chinese-linked operation reportedly compromised systems handling lawful-surveillance requests, siphoned data involving U.S. presidential campaigns and candidates, and expanded beyond the United States.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.