Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Hacker groups and malware
- Salt Typhoon
- Industries
- SaaS & technologyGovernment
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
Two Senate committee leaders are introducing legislation to foster cybersecurity standards for the telecommunications sector nearly two years after the landmark Salt Typhoon campaign was made public.
First reported by CyberScoop, Virginia Sen. Mark Warner, the top Democrat on the Intelligence Committee, and Texas Sen. Ted Cruz, the GOP chairman of the Commerce, Science and Technology panel, are introducing the Telecommunications Cybersecurity and Resilience Act.
“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient. This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day.”
Federal officials have repeatedly warned that Salt Typhoon — the Chinese group blamed for the massive and “indiscriminate” espionage campaign that hit major telecom carriers and siphoned data from presidential campaigns and candidates — remains a threat to this day.
Yet some cyber officials have worried that public apathy over the attacks has stifled momentum for telecom security rules. In one case the Trump administration has rolled them back.
The Warner-Cruz legislation takes the approach of trying to improve telecom security with voluntary measures jointly developed by government and industry.
“Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” Cruz said. “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.”
Their bill would create a telecom cybersecurity working group within the National Telecommunications and Information Administration to bring together carriers, suppliers, experts and relevant government agencies.
The working group would develop voluntary industry-wide best practices within 18 months of passage of the bill, which would be reviewed for updates every two years or after major incidents.
The best practices would “focus solely on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities,” according to the legislation, and would be in line with existing federal cybersecurity risk management frameworks.
The working group would also create a voluntary certification process through independent third-party assessors that companies could choose to use.
“What is missing” now, according to a summary of the bill, “is a common, telecom sector-specific set of best practices that brings that expertise together and can evolve as threats and technology change. Building on industry’s familiarity with security development and threat information sharing, this bill would bring stakeholders — government and private sector — together to develop and maintain effective techniques and practices to secure networks.”
Latest Podcasts
Government
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
CISA outlines improvement plan for CVE program
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Pentagon cyber chief: The demand far exceeds supply
Technology
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
Citing China, President Trump doubles down on hands-off approach to AI regulation
Researchers use AI to find widespread software decoder flaw
The AI hacking apocalypse is not inevitable
Threats
Ryuk ransomware operator sentenced to 2 years in prison
ShinyHunters claims attack on FBI exposes almost all agents
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Policy
Originally published by CyberScoop. © CyberScoop. Written by Tim Starks.
Fastnexa security experts
Worried Salt Typhoon could come after your company?
We test your defences the way groups like Salt Typhoon actually break in, then help you close the gaps before they find them.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-24 14:00 UTC
Related stories
- Apple patches CoreGraphics zero-day flaw exploited in attacks
BleepingComputer · 2026-09-29
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The Hacker News · 2026-09-29
- OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
The Hacker News · 2026-09-29
- One Packet Can Crash OT Servers in Industrial Sectors
Dark Reading · 2026-09-28