{"id":9599,"date":"2024-08-02T17:56:34","date_gmt":"2024-08-02T16:56:34","guid":{"rendered":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/?p=9599"},"modified":"2024-08-20T18:00:53","modified_gmt":"2024-08-20T17:00:53","slug":"mobile-telecom-security-landscape-blog-august-24","status":"publish","type":"post","link":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/","title":{"rendered":"Mobile Telecom Security Landscape Blog: August 24"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-welcome-to-our-august-blog-this-month-we-discuss-activity-underway-to-boost-the-security-of-border-gateway-protocol-bgp-share-some-thoughts-on-the-recent-at-amp-t-data-breach-including-security-considerations-when-using-third-party-managed-service-suppliers-and-the-need-to-secure-bring-your-own-device-byod-arrangements\">Welcome to our August blog. This month, we discuss activity underway to boost the security of Border Gateway Protocol (BGP), share some thoughts on the recent AT&amp;T data breach, including security considerations when using third-party managed service suppliers and the need to secure Bring Your Own Device (BYOD) arrangements.<\/h5>\n\n\n\n<p>The Federal Communications Commission (FCC) has&nbsp;<a href=\"https:\/\/www.fcc.gov\/document\/fcc-proposes-internet-routing-security-reporting-requirements\">released<\/a>&nbsp;a proposal aimed at bolstering the security of US networks against cyberattacks by improving internet routing security.&nbsp; The new initiative mandates that internet service providers produce confidential reports detailing their efforts and plans to address vulnerabilities in the BGP.&nbsp; BGP is used to enable routers connecting internet Autonomous Systems (AS) to know how to route to each other.&nbsp; Some BGP implementations assume that another AS is trusted and is telling \u2018the truth\u2019 about connectivity. Anyone is allowed to advertise a better route, whether maliciously or accidentally. &nbsp;In last month\u2019s blog post, I mentioned that I had been fortunate to hear some great talks at the recent 2024 Telecom &amp; Digital Infrastructure Security Forum.&nbsp; One of those talks was from the <a href=\"https:\/\/www.enisa.europa.eu\/events\/4th-telecom-security-forum\/rpki-enisa-may-2024-to-upload.pdf\">RIPE Network Coordination Centre<\/a>, which addressed a contribution towards strengthening BGP.&nbsp; Resource Public Key Infrastructure (RPKI) is a security layer in BGP routing that utilises X.509 certificates as cryptographic trust for routing ownership where the owners have a publicly available identifier.<strong> &nbsp;&nbsp;<\/strong>RPKI can be used to verify the origin of BGP routing announcements.&nbsp; RPKI provides part of the strengthening of BGP, but more adoption is needed and, in time, full BGP path validation.<\/p>\n\n\n\n<p><a href=\"https:\/\/otp.tools.investis.com\/clients\/us\/atnt2\/sec\/sec-show.aspx?Type=page&amp;FilingId=17677638-10542-13686&amp;CIK=0000732717&amp;Index=11100\">AT&amp;T recently reported a major security breach<\/a>.&nbsp; On April 19, 2024, AT&amp;T Inc. (\u201cAT&amp;T\u201d) learned that a threat actor claimed to have unlawfully accessed and copied AT&amp;T call logs. AT&amp;T immediately activated its incident response process to investigate and retained external cybersecurity experts to assist. Based on its investigation, AT&amp;T believes that threat actors unlawfully accessed an AT&amp;T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&amp;T records of customer call and text interactions that occurred between approximately May 1 and October 31, 2022, as well as on January 2, 2023.&nbsp; This attack on the supply chain service provider highlights the ongoing need to focus on the full range of third-party suppliers.&nbsp;<\/p>\n\n\n\n<p>One of the most concise of recent documents is the CISA, NSA, FBI and international cyber authorities\u2019 <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-nsa-fbi-and-international-cyber-authorities-issue-cybersecurity-advisory\">cybersecurity advisory to protect managed service providers and customers<\/a> including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Prevent initial compromise<\/li>\n\n\n\n<li>Enable\/improve monitoring and logging processes<\/li>\n\n\n\n<li>Enforce multifactor authentication (MFA)<\/li>\n\n\n\n<li>Manage internal architecture risks and segregate internal networks<\/li>\n\n\n\n<li>Organisations should apply the principle of least privilege<\/li>\n\n\n\n<li>Deprecate obsolete accounts and infrastructure<\/li>\n\n\n\n<li>Apply updates<\/li>\n\n\n\n<li>Backup systems and data<\/li>\n\n\n\n<li>Develop and exercise incident response and recovery plans<\/li>\n\n\n\n<li>Understand and proactively manage supply chain risk<\/li>\n\n\n\n<li>Promote transparency<\/li>\n\n\n\n<li>Manage account authentication and authorisation.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/www.cyber.gov.au\/sites\/default\/files\/2023-03\/PROTECT%20-%20How%20to%20Manage%20Your%20Security%20When%20Engaging%20a%20Managed%20Service%20Provider%20%28October%202021%29.pdf\">The Australian Signals Directorate (ASD) have released a guide<\/a>, <em>How to Manage Your Security When Engaging a Managed Service Provider.&nbsp; <\/em>It contains a number of suggested mitigation strategies including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Make sure your own network is secure<\/li>\n\n\n\n<li>Get security in the contract<\/li>\n\n\n\n<li>Ensure your contract requires your MSP to maintain a good internal security culture<\/li>\n\n\n\n<li>Control MSP access to your network<\/li>\n\n\n\n<li>Mitigate the impact of stolen or abused credentials<\/li>\n\n\n\n<li>Ensure visibility of MSP actions on your network<\/li>\n\n\n\n<li>Plan for a cyber security incident.<\/li>\n<\/ul>\n\n\n\n<p>Also available from the Canadian Centre for Cyber Security is the report, <a href=\"https:\/\/www.cyber.gc.ca\/sites\/default\/files\/cyber\/publications\/itsm50030-e.pdf\"><em>Cyber Security Considerations For Consumers of Managed Services<\/em><\/a><em>.&nbsp; <\/em>The report covers a range of topics including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Data security<\/li>\n\n\n\n<li>Legal compliance<\/li>\n\n\n\n<li>Service provider assessments<\/li>\n\n\n\n<li>Access control<\/li>\n\n\n\n<li>Encryption<\/li>\n\n\n\n<li>Incident response<\/li>\n\n\n\n<li>Business continuity and disaster recovery<\/li>\n\n\n\n<li>Supply chain integrity<\/li>\n\n\n\n<li>Exit strategies<\/li>\n\n\n\n<li>Data destruction.<\/li>\n<\/ul>\n\n\n\n<p>BYOD allows employees and contractors to use personal devices for work. <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/unc5537-snowflake-data-theft-extortion\">It has been found<\/a> that compromised credentials are the initial access vector in many breaches.&nbsp; These credentials have been gathered in a variety of ways, one of which has been abusing a company\u2019s BYOD policy.&nbsp; There are ways of securely implementing BYOD policies, for example, with virtual environments, least privilege, use of multi-factor authentication and managing data and permissions on employee exit. &nbsp;However, it is all too common for this to be overlooked. &nbsp;In the case of Snowflake, contractors used insecure personal devices to connect to customer databases. &nbsp;The contractors, who had used their laptops for other purposes (e.g. watching pirated content), exposed their devices to Infostealer Malware. &nbsp;This hands over login credentials to threat actors, which they can use to access database instances \u2013 often with the contractor\u2019s administrator\/IT privileges.<\/p>\n\n\n\n<p><strong><br>If you\u2019d like to discuss these themes or to get more closely involved, please email&nbsp;<a href=\"mailto:security@gsma.com\">security@gsma.com<\/a>.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome to our August blog. This month, we discuss activity underway to boost the security of Border Gateway Protocol (BGP), share some thoughts on the recent AT&amp;T data breach, including security considerations when using third-party managed service suppliers and the need to secure Bring Your Own Device (BYOD) arrangements. The Federal Communications Commission (FCC) has&nbsp;released&nbsp;a [&hellip;]<\/p>\n","protected":false},"author":53,"featured_media":8336,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","footnotes":""},"categories":[1505],"tags":[],"algolia_discover_type":[1549],"class_list":["post-9599","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-latest-news","algolia_discover_type-article"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.3 (Yoast SEO v24.3) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mobile Telecom Security Landscape Blog: August 24 - Security<\/title>\n<meta name=\"description\" content=\"Discuss activity underway to boost the security of Border Gateway Protocol (BGP), share some thoughts on the recent AT&amp;T data breach, including security considerations when using third-party managed service suppliers and the need to secure Bring Your Own Device (BYOD) arrangements.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mobile Telecom Security Landscape Blog: August 24 - Security\" \/>\n<meta property=\"og:description\" content=\"Discuss activity underway to boost the security of Border Gateway Protocol (BGP), share some thoughts on the recent AT&amp;T data breach, including security considerations when using third-party managed service suppliers and the need to secure Bring Your Own Device (BYOD) arrangements.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/\" \/>\n<meta property=\"og:site_name\" content=\"Security\" \/>\n<meta property=\"article:published_time\" content=\"2024-08-02T16:56:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-20T17:00:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"sfishwick@gsma.com\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"sfishwick@gsma.com\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Mobile Telecom Security Landscape Blog: August 24 - Security","description":"Discuss activity underway to boost the security of Border Gateway Protocol (BGP), share some thoughts on the recent AT&T data breach, including security considerations when using third-party managed service suppliers and the need to secure Bring Your Own Device (BYOD) arrangements.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/","og_locale":"en_GB","og_type":"article","og_title":"Mobile Telecom Security Landscape Blog: August 24 - Security","og_description":"Discuss activity underway to boost the security of Border Gateway Protocol (BGP), share some thoughts on the recent AT&T data breach, including security considerations when using third-party managed service suppliers and the need to secure Bring Your Own Device (BYOD) arrangements.","og_url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/","og_site_name":"Security","article_published_time":"2024-08-02T16:56:34+00:00","article_modified_time":"2024-08-20T17:00:53+00:00","og_image":[{"width":900,"height":300,"url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1.png","type":"image\/png"}],"author":"sfishwick@gsma.com","twitter_card":"summary_large_image","twitter_misc":{"Written by":"sfishwick@gsma.com","Estimated reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/","name":"Mobile Telecom Security Landscape Blog: August 24 - Security","isPartOf":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/#primaryimage"},"image":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1-e1744681521650.png","datePublished":"2024-08-02T16:56:34+00:00","dateModified":"2024-08-20T17:00:53+00:00","author":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#\/schema\/person\/779a7ff304b557a1b5fb9b7e5b34f150"},"description":"Discuss activity underway to boost the security of Border Gateway Protocol (BGP), share some thoughts on the recent AT&T data breach, including security considerations when using third-party managed service suppliers and the need to secure Bring Your Own Device (BYOD) arrangements.","inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/latest-news\/mobile-telecom-security-landscape-blog-august-24\/#primaryimage","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1-e1744681521650.png","contentUrl":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1-e1744681521650.png","width":352,"height":190,"caption":"People working at computer centre"},{"@type":"WebSite","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#website","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/","name":"Security","description":"GSMA Security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#\/schema\/person\/779a7ff304b557a1b5fb9b7e5b34f150","name":"sfishwick@gsma.com","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/053fecc6339b359a923239637a042baf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/053fecc6339b359a923239637a042baf?s=96&d=mm&r=g","caption":"sfishwick@gsma.com"}}]}},"featured_image_url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2024\/05\/Security-blog-1-1-e1744681521650.png","_links":{"self":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts\/9599","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/users\/53"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/comments?post=9599"}],"version-history":[{"count":3,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts\/9599\/revisions"}],"predecessor-version":[{"id":9602,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts\/9599\/revisions\/9602"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/media\/8336"}],"wp:attachment":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/media?parent=9599"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/categories?post=9599"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/tags?post=9599"},{"taxonomy":"algolia_discover_type","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/algolia_discover_type?post=9599"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}