Visualização normal

Antes de ontemStream principal
  • ✇Security Affairs
  • FCC Restricts New Foreign Robots and Inverters Over Security Risks Pierluigi Paganini
    The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain terms, that means new models in those categories generally can’t get the equipment authorization they need for import, marketing, or sale in the US, although already authorized devices can still be sold and used.
     

FCC Restricts New Foreign Robots and Inverters Over Security Risks

30 de Julho de 2026, 07:10

The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029.

The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain terms, that means new models in those categories generally can’t get the equipment authorization they need for import, marketing, or sale in the US, although already authorized devices can still be sold and used.

“The Federal Communications Commission’s Office of Engineering and Technology (OET) announces that certain prohibitions contained in 47 CFR §§ 2.932(b) and 2.1043(b) will not apply for now to certain foreign-produced advanced robotic devices and power inverters. All advanced robotic devices and power inverters authorized for use in the United States may continue to receive software and firmware updates that mitigate harm to U.S. consumers at least until January 1, 2029.” reads the FCC public notice. “These include all software and firmware updates to ensure the continued functionality of the devices, such as those that patch vulnerabilities and facilitate compatibility with different operating systems.”

The FCC Covered List is a registry of communications equipment and services considered potential national security or public safety risks in the United States. Created under the Secure and Trusted Communications Networks Act of 2019, it targets foreign-produced technologies that may raise concerns over espionage, cyber vulnerabilities, foreign influence, or supply-chain risks. Devices added to the list may face restrictions, including limits on FCC authorization for new products, additional approval requirements for hardware or software changes, and greater scrutiny for companies using these technologies.

That waiver matters because the FCC’s default rules would otherwise block permissive changes on covered equipment, including software and firmware updates that fix vulnerabilities or keep devices working with different operating systems. The agency is trying to avoid a stupid outcome where security updates get trapped behind a rule meant to cut off risky gear.

“OET finds that special circumstances warrant a deviation from the general rules and the public interest would be better served by waiving prohibitions on these Class I and Class II permissive changes in these circumstances.” continues the notice.

The notice is narrow, though. It only covers already authorized devices, and grantees still have to follow the rest of the FCC’s rules, including the normal requirements for Class II permissive changes, test results, minimum performance, and certification statements. So this is relief, not a free pass.

The FCC also drew a line around what counts as covered hardware. For robots, the definition is broader than just “mobile robots” and excludes connected road vehicles, rail-only equipment, uncrewed aircraft, underwater vehicles, FDA-regulated medical and mobility devices, and fixed industrial arms like SCARA, gantry, and delta systems. For inverters, the rule covers systems that convert DC to AC or the reverse and include remote communication, control, sensing, data collection, or monitoring features.

“OET believes that analogous concerns regarding the continued safe operation of existing models of UAS, UAS critical components, and routers that OET described in the prior UAS Waiver and Router Waiver also apply equally to foreign-produced power inverters and advanced robotic devices.” states FCC. “Therefore, OET concludes that waiving our prohibitions with regard to software and firmware Class I and II permissive changes that mitigate harm to U.S. consumers for Covered Power Inverters and Covered Advanced Robotic Devices through at least January 1, 2029, is warranted and in the public interest.”

The FCC’s move is preventive, not reactive. It doesn’t name a confirmed active campaign against deployed robots or inverters, but it does rely on prior security research and supply-chain concerns to justify the action. That includes cases where researchers found exposure of camera feeds, microphone audio, maps, BLE attack paths, API-driven remote control, and inverter risks tied to remote access and grid instability.

“We clarify that this waiver only applies to the prohibitions on Class I or Class II permissive changes for already-authorized devices. Grantees whose devices are subject to this waiver must still comply with other relevant FCC rules.” concludes the notice.

The agency is also making clear that this is part of a wider pattern. The action follows earlier Covered List moves on foreign-produced drones and consumer routers, so the FCC is steadily using the same national-security framework across more device classes. The message is simple: if the device can be reached, updated, or remotely controlled, the supply chain is now part of the threat model.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Covered List)

New FCC Proposal Pits Phone Privacy Against Fraud Prevention

17 de Julho de 2026, 11:39

The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy.

The post New FCC Proposal Pits Phone Privacy Against Fraud Prevention appeared first on TechRepublic.

Telco Privacy Violation? Fine! No, Telco Privacy Violation, Fine. Supreme Court to Determine if FCC Can Charge Telcos for Data Breaches

23 de Abril de 2026, 08:19
data pipeline, blindness, data blindness, compliance,data, governance, framework, companies, privacy, databases, AWS, UnitedHealth ransomware health care UnitedHealth CISO

The intersection of constitutional law and cybersecurity enforcement, specifically the Seventh Amendment right to a jury trial in regulatory data privacy cases.
Central Conflict: Whether federal agencies (like the FCC, SEC, or FTC) can administratively impose monetary penalties for data misuse without a jury, or if such actions are "Suits at common law" requiring Article III court proceedings.

The post Telco Privacy Violation? Fine! No, Telco Privacy Violation, Fine. Supreme Court to Determine if FCC Can Charge Telcos for Data Breaches appeared first on Security Boulevard.

  • ✇Firewall Daily – The Cyber Express
  • FCC Proposes Tougher KYC Rules to Crack Down on Illegal Robocalls Samiksha Jain
    The Federal Communications Commission (FCC) is proposing stricter Know-Your-Customer (KYC) rules for robocalls as part of a broader effort to curb illegal calls and protect consumers. In a newly released Further Notice of Proposed Rulemaking, the agency outlined plans to tighten requirements for originating voice service providers, which are considered the first line of defense against unlawful robocalls. The proposal reflects growing concern that existing KYC rules for robocalls are not being c
     

FCC Proposes Tougher KYC Rules to Crack Down on Illegal Robocalls

KYC Rules for Robocalls

The Federal Communications Commission (FCC) is proposing stricter Know-Your-Customer (KYC) rules for robocalls as part of a broader effort to curb illegal calls and protect consumers. In a newly released Further Notice of Proposed Rulemaking, the agency outlined plans to tighten requirements for originating voice service providers, which are considered the first line of defense against unlawful robocalls. The proposal reflects growing concern that existing KYC rules for robocalls are not being consistently enforced, allowing bad actors to exploit gaps in the system. The FCC emphasized that stopping illegal calls before they enter the network remains the most effective way to reduce fraud and abuse.

Why the FCC Is Expanding KYC Rules for Robocalls

Under current FCC robocall regulations, voice service providers are required to take “affirmative, effective” steps to know their customers. However, regulators say some providers are failing to carry out adequate checks, resulting in a surge of illegal robocalls that defraud consumers and expose telecom networks to misuse. “Combatting illegal calls is our top consumer protection priority, and we are taking a holistic approach by attacking them at every point in their lifecycle.” The FCC noted that weak KYC rules for robocalls not only enable scams but also make it harder for law enforcement to track criminal activities, including drug trafficking and human exploitation that rely on anonymous communication channels.

Proposed Changes to KYC Rules for Robocalls

The FCC is seeking public comment on several measures aimed at strengthening KYC rules for robocalls and improving telecom KYC compliance. One key proposal is to require providers to collect more detailed customer information before granting access to calling services. This includes name, physical address, government-issued identification number, and an alternate contact number for all new and renewing customers. For high-volume callers, such as businesses or bulk calling services, the FCC is considering additional requirements. These may include collecting information on how the service will be used—such as marketing or political campaigns—as well as technical data like IP addresses used to place calls. The Commission believes these enhanced Know-Your-Customer rules for robocalls could deter fraudsters from entering the network and make it easier to identify them if illegal activity occurs.

Verification, Monitoring, and Data Retention

Beyond data collection, the FCC is also proposing stricter verification and monitoring under its updated KYC rules for robocalls. Providers may be required to verify customer identities using supporting documents such as government-issued IDs or business registration records. The agency is also exploring whether companies should retain KYC records for up to four years after a customer relationship ends, allowing time for investigations into illegal robocalls. Another key focus is ongoing monitoring. The FCC is considering whether providers should re-verify customer information when unusual activity is detected, such as sudden spikes in call volume or changes in traffic patterns. These measures aim to ensure that telecom networks are not continuously exploited by bad actors using false or stolen identities.

Tougher Penalties to Enforce Compliance

To strengthen enforcement, the FCC has proposed financial penalties tied directly to violations of KYC rules for robocalls. The agency is considering a base fine of $2,500 per illegal call, aligning penalties with the scale of harm caused. This per-call penalty structure is designed to discourage large-scale robocall operations, where millions of fraudulent calls can generate significant profits. The FCC believes that stronger enforcement will push providers to take telecom KYC compliance more seriously and close existing loopholes.

Recent Enforcement Highlights Gaps

The push for stronger KYC rules for robocalls comes amid ongoing enforcement challenges. In a recent case, the FCC proposed a $4.5 million fine against Voxbeam Telecommunications for allegedly routing illegal robocalls into U.S. networks. The investigation found that Voxbeam accepted traffic from Axfone, a Czech-based provider not listed in the FCC’s Robocall Mitigation Database. Under existing rules, such traffic should have been blocked, raising concerns about gaps in compliance and oversight. If adopted, the new rules could significantly reshape how voice service providers onboard and monitor customers, bringing telecom practices closer to the stricter identity verification standards already seen in the financial sector.
❌
❌