{"id":9316,"date":"2024-06-07T12:47:41","date_gmt":"2024-06-07T11:47:41","guid":{"rendered":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/?p=9316"},"modified":"2025-02-06T21:37:29","modified_gmt":"2025-02-06T21:37:29","slug":"mobile-telecom-security-landscape-blog-june-24","status":"publish","type":"post","link":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/","title":{"rendered":"Mobile Telecom Security Landscape Blog: June 24"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-this-blog-post-discusses-virtualisation-security-living-off-the-land-attacks-gsma-s-recent-update-to-its-baseline-controls-an-approach-to-security-testing-the-artificial-intelligence-exchange-and-post-quantum-telco-network-activity\"><strong>This blog post discusses virtualisation security, \u2018living off the land\u2019 attacks, GSMA\u2019s recent update to its baseline controls, an approach to security testing, the artificial intelligence exchange and post-quantum telco network activity.<\/strong><\/h4>\n\n\n\n<p>VMware ESXi, Workstation, and Fusion contain a vulnerability<a id=\"_ftnref1\" href=\"#_ftn1\">[1]<\/a> in the XHCI USB controller.&nbsp; VMware has evaluated the severity of this issue to be in the&nbsp;Critical severity range&nbsp;with a maximum CVSSv3 base score of&nbsp;9.3&nbsp;for Workstation\/Fusion and in the&nbsp;Important severity range&nbsp;with a maximum CVSSv3 base score of&nbsp;8.4&nbsp;for ESXi.&nbsp;A security fix has been made available and a prompt response is advised.&nbsp; VMware ESXi provides a bare-metal hypervisor&nbsp;(ie it sits between the hardware and the operating system) that has direct access to and control of underlying resources.&nbsp; A&nbsp;hypervisor is a type of virtualisation software that supports the creation and management of&nbsp;virtual machines&nbsp;(VMs) by separating a computer\u2019s software from its hardware.&nbsp;<\/p>\n\n\n\n<p>The US Cybersecurity &amp; Infrastructure Security Agency (CISA) and the National Security Agency (NSA) recently released five joint Cybersecurity Information Sheets (CSIs) that aim to provide organisations with best practices and\/or mitigations to improve their cloud security.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/media.defense.gov\/2024\/Mar\/07\/2003407866\/-1\/-1\/0\/CSI-CloudTop10-Identity-Access-Management.PDF\">Use Secure Cloud Identity and Access M<\/a><a href=\"https:\/\/media.defense.gov\/2024\/Mar\/07\/2003407866\/-1\/-1\/0\/CSI-CloudTop10-Identity-Access-Management.PDF\" target=\"_blank\" rel=\"noreferrer noopener\">anagement Practices<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/media.defense.gov\/2024\/Mar\/07\/2003407858\/-1\/-1\/0\/CSI-CloudTop10-Key-Management.PDF\">Use Secure Cloud Key Management Pra<\/a><a href=\"https:\/\/media.defense.gov\/2024\/Mar\/07\/2003407858\/-1\/-1\/0\/CSI-CloudTop10-Key-Management.PDF\" target=\"_blank\" rel=\"noreferrer noopener\">ctices<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/media.defense.gov\/2024\/Mar\/07\/2003407861\/-1\/-1\/0\/CSI-CloudTop10-Network-Segmentation.PDF\" target=\"_blank\" rel=\"noreferrer noopener\">Implement Network Segmentation and Encryption in Cloud Environments<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/media.defense.gov\/2024\/Mar\/07\/2003407862\/-1\/-1\/0\/CSI-CloudTop10-Secure-Data.PDF\">Secure D<\/a><a href=\"https:\/\/media.defense.gov\/2024\/Mar\/07\/2003407862\/-1\/-1\/0\/CSI-CloudTop10-Secure-Data.PDF\" target=\"_blank\" rel=\"noreferrer noopener\">ata in the Cloud<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/media.defense.gov\/2024\/Mar\/07\/2003407859\/-1\/-1\/0\/CSI-CloudTop10-Managed-Service-Providers.PDF\">Mitigate Risks from Managed Service Provide<\/a><a href=\"https:\/\/media.defense.gov\/2024\/Mar\/07\/2003407859\/-1\/-1\/0\/CSI-CloudTop10-Managed-Service-Providers.PDF\" target=\"_blank\" rel=\"noreferrer noopener\">rs in Cloud Environments<\/a><\/li>\n<\/ul>\n\n\n\n<p>A report<a id=\"_ftnref1\" href=\"#_ftn1\">[2]<\/a> earlier this year highlighted that state-sponsored cyber actors are seeking to pre-position themselves on telecom networks for later disruptive or destructive cyberattacks.&nbsp; The report documented how hackers were inside Ukrainian telecoms giant Kyivstar\u2019s system from at least May last year.&nbsp; A later attack disabled services for some 24 million users for a number of days from 12 December.&nbsp;<\/p>\n\n\n\n<p>A type of tradecraft known as \u2018living off the land\u2019 (LOTL) involves the abuse of native tools and processes on systems and allows attackers to operate discreetly.&nbsp; Malicious activity aims to blend in with legitimate system and network behaviour, and the lack of conventional indicators of compromise (IOCs) associated with the activity makes it difficult for operators to detect, allowing for long-term undiscovered persistence.&nbsp; Part of this challenge is in identifying a relatively small volume of malicious activity within large volumes of log data. &nbsp;This persistent access can allow for data extraction, traffic monitoring, and later destructive attacks that can disable services.<\/p>\n\n\n\n<p>The release of a joint guide<a id=\"_ftnref1\" href=\"#_ftn1\">[3]<\/a> for network defenders focuses on how to mitigate identified gaps and how defensive \u2018blue\u2019 teams can proactively detect and hunt for LOTL activity through activities such as conducting behavioural analytics, anomaly detection, and proactive hunting.&nbsp; Other guidance includes hardening systems, tuning end-point detection systems, network segmentation, operating least privilege and establishing and maintaining baselines of network, user, administrative, and application activity.<\/p>\n\n\n\n<p>GSMA\u2019s Baseline Controls guidelines, FS.31<a id=\"_ftnref1\" href=\"#_ftn1\">[4]<\/a>, have benefitted from a significant update.&nbsp; FS.31 outlines a recommended set of security controls, which map to threats described in FS30 (a GSMA-member document), that network operators should consider deploying along with references to relevant standards and other best practice resources. The solution description for each control identifies specific advice that allows the operator to fulfil the control objectives. The changes include the addition of new controls pertaining to edge computing, network function virtualisation, network slicing and network orchestration. In total, 85 new controls have been added, and guidance has been enhanced for 29 solutions.<\/p>\n\n\n\n<p>The UK Telecoms Lab (UKTL) is a&nbsp;telecoms security lab, established by the UK Government Department for Science, Innovation and Technology (DSIT)&nbsp;and operated by the National Physical Laboratory (NPL). This is a national facility, located in Solihull, and aims to provide test and evaluation capability to enhance confidence in the resilience and security of telecoms systems deployed in the UK.&nbsp; The UKTL has been established to support the UK government\u2019s security and diversification policy and to assist the UK supply chain diversification ambitions. It is anticipated that some form of international cooperation will be established.<\/p>\n\n\n\n<p>The OWASP Artificial Intelligence Exchange (AI)<a id=\"_ftnref1\" href=\"#_ftn1\">[5]<\/a> provides an open-sourced discussion on the security of AI. It is an open, collaborative project that aims to advance the development of AI security standards and regulations (by providing an overview of AI threats, vulnerabilities and controls).&nbsp;Large Language Models AI Cybersecurity &amp; Governance Checklist<a id=\"_ftnref1\" href=\"#_ftn1\">[6]<\/a>, The OWASP Top 10 for LLMs<a id=\"_ftnref2\" href=\"#_ftn2\">[7]<\/a> is a list of the most critical vulnerabilities found in applications utilising LLMs.<\/p>\n\n\n\n<p>GSMA\u2019s Post Quantum Telco Networks group have released their latest whitepaper, PQ.03 Post Quantum Cryptography \u2013 Guidelines for Telecom Use Cases<a id=\"_ftnref1\" href=\"#_ftn1\">[8]<\/a>.&nbsp; The scope of this document is to provide a set of best practice guidelines that can be used to support the journey to quantum safe cryptography in the context of the telecom ecosystem.&nbsp; The work builds directly on the outcome of the first impact assessment whitepaper<a id=\"_ftnref2\" href=\"#_ftn2\">[9]<\/a> and takes into consideration the risk assessment framework(s) being adopted by the wider industry and the implementation roadmap for post-quantum cryptography.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-if-you-d-like-to-discuss-or-to-get-more-closely-involved-please-email-security-gsma-com\"><strong>If you\u2019d like to discuss or to get more closely involved, please email <a href=\"mailto:security@gsma.com\">security@gsma.com<\/a>.<\/strong><\/h4>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><a id=\"_ftn1\" href=\"#_ftnref1\">[1]<\/a> <a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2024-0006.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2024-0006.html<\/a><\/p>\n\n\n\n<p><a id=\"_ftn1\" href=\"#_ftnref1\">[2]<\/a> <a href=\"https:\/\/www.euractiv.com\/section\/europe-s-east\/news\/russian-hackers-were-inside-ukraine-telecoms-giant-for-months-cyber-spy-chief\/\">https:\/\/www.euractiv.com\/section\/europe-s-east\/news\/russian-hackers-were-inside-ukraine-telecoms-giant-for-months-cyber-spy-chief\/<\/a><\/p>\n\n\n\n<p><a id=\"_ftn1\" href=\"#_ftnref1\">[3]<\/a> <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2024-02\/Joint-Guidance-Identifying-and-Mitigating-LOTL_V3508c.pdf\">https:\/\/www.cisa.gov\/sites\/default\/files\/2024-02\/Joint-Guidance-Identifying-and-Mitigating-LOTL_V3508c.pdf<\/a><\/p>\n\n\n\n<p><a id=\"_ftn1\" href=\"#_ftnref1\">[4]<\/a> <a href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/resources\/fs-31-gsma-baseline-security-controls\/\">https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/resources\/fs-31-gsma-baseline-security-controls\/<\/a><\/p>\n\n\n\n<p><a id=\"_ftn1\" href=\"#_ftnref1\">[5]<\/a> <a href=\"https:\/\/owaspai.org\/\">https:\/\/owaspai.org\/<\/a><\/p>\n\n\n\n<p><a id=\"_ftn1\" href=\"#_ftnref1\">[6]<\/a> <a href=\"https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/llm-top-10-governance-doc\/LLM_AI_Security_and_Governance_Checklist-v1.pdf\">https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/llm-top-10-governance-doc\/LLM_AI_Security_and_Governance_Checklist-v1.pdf<\/a><\/p>\n\n\n\n<p><a id=\"_ftn2\" href=\"#_ftnref2\">[7]<\/a> <a href=\"https:\/\/llmtop10.com\/\">https:\/\/llmtop10.com\/<\/a><\/p>\n\n\n\n<p><a id=\"_ftn1\" href=\"#_ftnref1\">[8]<\/a> <a href=\"https:\/\/www.gsma.com\/newsroom\/gsma_resources\/pq-03-post-quantum-cryptography-guidelines-for-telecom-use-cases\/\">https:\/\/www.gsma.com\/newsroom\/gsma_resources\/pq-03-post-quantum-cryptography-guidelines-for-telecom-use-cases\/<\/a><\/p>\n\n\n\n<p><a id=\"_ftn2\" href=\"#_ftnref2\">[9]<\/a> <a href=\"https:\/\/www.gsma.com\/newsroom\/wp-content\/uploads\/PQ.1-Post-Quantum-Telco-Network-Impact-Assessment-Whitepaper-Version1.0.pdf\">https:\/\/www.gsma.com\/newsroom\/wp-content\/uploads\/PQ.1-Post-Quantum-Telco-Network-Impact-Assessment-Whitepaper-Version1.0.pdf<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This blog post discusses virtualisation security, \u2018living off the land\u2019 attacks, GSMA\u2019s recent update to its baseline controls, an approach to security testing, the artificial intelligence exchange and post-quantum telco network activity. VMware ESXi, Workstation, and Fusion contain a vulnerability[1] in the XHCI USB controller.&nbsp; VMware has evaluated the severity of this issue to be [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":8336,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","footnotes":"[]"},"categories":[1505],"tags":[],"algolia_discover_type":[1549],"class_list":["post-9316","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-latest-news","algolia_discover_type-article"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.3 (Yoast SEO v24.3) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mobile Telecom Security Landscape Blog: June 24 - Security<\/title>\n<meta name=\"description\" content=\"This blog post discusses virtualisation security, \u2018living off the land\u2019 attacks, GSMA\u2019s recent update to its baseline controls, an approach to security testing, the artificial intelligence exchange and post-quantum telco network activity.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mobile Telecom Security Landscape Blog: June 24 - Security\" \/>\n<meta property=\"og:description\" content=\"This blog post discusses virtualisation security, \u2018living off the land\u2019 attacks, GSMA\u2019s recent update to its baseline controls, an approach to security testing, the artificial intelligence exchange and post-quantum telco network activity.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/\" \/>\n<meta property=\"og:site_name\" content=\"Security\" \/>\n<meta property=\"article:published_time\" content=\"2024-06-07T11:47:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-06T21:37:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Sian\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sian\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Mobile Telecom Security Landscape Blog: June 24 - Security","description":"This blog post discusses virtualisation security, \u2018living off the land\u2019 attacks, GSMA\u2019s recent update to its baseline controls, an approach to security testing, the artificial intelligence exchange and post-quantum telco network activity.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/","og_locale":"en_GB","og_type":"article","og_title":"Mobile Telecom Security Landscape Blog: June 24 - Security","og_description":"This blog post discusses virtualisation security, \u2018living off the land\u2019 attacks, GSMA\u2019s recent update to its baseline controls, an approach to security testing, the artificial intelligence exchange and post-quantum telco network activity.","og_url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/","og_site_name":"Security","article_published_time":"2024-06-07T11:47:41+00:00","article_modified_time":"2025-02-06T21:37:29+00:00","og_image":[{"width":900,"height":300,"url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1.png","type":"image\/png"}],"author":"Sian","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sian","Estimated reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/","name":"Mobile Telecom Security Landscape Blog: June 24 - Security","isPartOf":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/#primaryimage"},"image":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1-e1744681521650.png","datePublished":"2024-06-07T11:47:41+00:00","dateModified":"2025-02-06T21:37:29+00:00","author":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#\/schema\/person\/9a2c754a3d1e5ae893b6f972f3ac6f9a"},"description":"This blog post discusses virtualisation security, \u2018living off the land\u2019 attacks, GSMA\u2019s recent update to its baseline controls, an approach to security testing, the artificial intelligence exchange and post-quantum telco network activity.","inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-june-24\/#primaryimage","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1-e1744681521650.png","contentUrl":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1-e1744681521650.png","width":352,"height":190,"caption":"People working at computer centre"},{"@type":"WebSite","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#website","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/","name":"Security","description":"GSMA Security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#\/schema\/person\/9a2c754a3d1e5ae893b6f972f3ac6f9a","name":"Sian","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/053fecc6339b359a923239637a042baf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/053fecc6339b359a923239637a042baf?s=96&d=mm&r=g","caption":"Sian"}}]}},"featured_image_url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1-e1744681521650.png","_links":{"self":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts\/9316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/comments?post=9316"}],"version-history":[{"count":13,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts\/9316\/revisions"}],"predecessor-version":[{"id":11753,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts\/9316\/revisions\/11753"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/media\/8336"}],"wp:attachment":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/media?parent=9316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/categories?post=9316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/tags?post=9316"},{"taxonomy":"algolia_discover_type","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/algolia_discover_type?post=9316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}