Detection on a Budget: Building Useful Visibility With Open-Source Tools
November 12, 2025Your SaaS Is Not Secure by Default: Locking Down the Cloud Control Plane
December 3, 2025Throughout 2025, the fallout from Salt Typhoon, a China-linked espionage campaign against telecommunications providers, continued to shape how governments think about critical-infrastructure security. The campaign compromised carrier networks across multiple countries, and Canadian authorities confirmed that Canadian telecommunications infrastructure was among the targets, including exploitation of network edge devices. This is not smash-and-grab crime. It is patient, strategic espionage.
Why Telecom Is the Prize
Telecommunications networks carry the communications of governments, businesses, and citizens, and they include lawful-intercept systems that, if compromised, expose exactly who is being monitored. Access to carrier infrastructure enables broad surveillance and positions an adversary to disrupt communications during a future crisis. Salt Typhoon favored persistence and stealth, living inside networks for extended periods.
What Defenders Can Learn
- Edge devices are the entry point. Routers, VPN concentrators, and perimeter gear were repeatedly targeted.
- Persistence beats speed. Detection must look for subtle, long-dwell anomalies.
- Segment and monitor internally. Assume the perimeter can be breached and limit how far an intruder can move.
- Log retention matters. Investigating a months-long intrusion requires logs that go back months.
Beyond the Carriers
While Salt Typhoon targeted large telecoms, the techniques generalize. Any Canadian organization running internet-facing edge devices should assume nation-state-grade adversaries are interested in the same weaknesses. The strategic lesson is that critical infrastructure defense is a shared responsibility, and the edge of your network is the front line.
Takeaway
Salt Typhoon shows that patient, well-resourced adversaries prize persistent access to communications infrastructure. Harden and patch edge devices, segment internal networks, retain logs long enough to investigate slow intrusions, and hunt for stealthy long-dwell activity.
