Read more of this story at Slashdot.
Intelligence View
⚡ tsecurity.de Intelligence
T-Mobile Exempts AT&T's DirecTV Now Service From Data Caps
An anonymous reader writes: One of the biggest selling points of ATT's DirecTV Now service is that it streams video without counting against data caps on the ATT mobile network. But T-Mobile USA customers will also be able to watch DirecTV…
Reagiere als Erste:r — dein Feedback zählt!
An anonymous reader writes: One of the biggest selling points of ATT's DirecTV Now service is that it streams video without counting against data caps on the ATT mobile network. But T-Mobile USA customers will also be able to watch DirecTV Now without using up data, the carrier announced yesterday. DirecTV Now is one of the latest services added to Binge On, which exempts dozens of video services from data caps as long as customers are willing to limit mobile viewing quality to about 480p. T-Mobile also promised to reimburse customers for DirecTV Now for 12 months if they port a phone number from the ATT network to T-Mobile and purchase at least two lines. This offer consists of a $35 monthly bill credit, enough to cover the DirecTV Now promotional price. This is a limited-time offer and cannot be combined with other offers like "Carrier Freedom," which reimburses customers for early termination fees when they switch to T-Mobile. "ATT wants you to think DirecTV is theirs exclusively, but that's a load of crap," Legere said in T-Mobile's press release yesterday. "Both DirecTV Now and the DirecTV apps stream free on T-Mobile with a faster, more advanced network that covers nearly every American. ATT is so distracted by their new businesses and DirecTV that they continue to ignore their 110 million wireless customers. Luckily, the Un-carrier's here to show them how to actually take care of customers!"
1. Sofort-Triage & Abwehrmaßnahmen
SOC Incident Playbook: Vulnerability Remediation & Verification
1 Warnungen
title: Detect Exploitation - T-Mobile Exempts AT&T's DirecTV Now Service From Data Caps
id: aa1864a9-feb6-4ed8-92fc-f1323d14f5cb
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-27
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessSyntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-27"
description = "YARA Signature for "
strings:
$str = "T-Mobile Exempts AT&T\'s DirecT" ascii wide
condition:
any of them
}Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("T-Mobile Exempts ATTs DirecTV Now Servic")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - countSyntax validiert (0 Fehler)
message: "*T-Mobile Exempts ATTs DirecTV Now Servic*"Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "T-Mobile Exempts ATTs DirecTV Now Servic"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc2. Cyber Threat Intelligence & Forensik
CTI Threat Relationship Graph3 Knoten / 2 Relationen
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:
Analyse für identifizierte Bedrohung auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
🛡️ Angriffsfläche & Exposure
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
⚡ Empfohlene Sofortmaßnahmen
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
Synthetische RAG-Antwort