Skip to main content

Share story

Policy Security Infrastructure

FCC Bans Foreign-Made Routers Over Cybersecurity Concerns

FCC Bans Foreign-Made Routers Over Cybersecurity Concerns Image: Primary
The Federal Communications Commission has added foreign-produced routers to its Covered List, effectively banning the sale of most new consumer routers manufactured outside the United States unless they receive specific exemptions from the Department of Defense or Department of Homeland Security. The FCC issued the update on March 23, citing "security gaps in foreign-made routers" as justification. The Commission referenced attacks by Chinese advanced persistent threat groups including Volt Typhoon, Flax Typhoon, and Salt Typhoon in its announcement. The ban marks a shift from the FCC's previous approach of targeting specific vendors, such as Huawei and Hytera in 2021. The new blanket prohibition affects nearly all imported consumer routers while exempting U.S.-manufactured devices like Starlink routers produced in Texas. Critics note the ban fails to distinguish between manufacturers with strong security records and those with histories of vulnerabilities. The Electronic Frontier Foundation argues the policy fails to address IoT and smart home devices, which are frequently compromised in botnet attacks. The group also warned that the ban could entrench existing market players and create problematic favoritism in exemption decisions. The FCC's action comes amid broader trade-related executive orders targeting foreign goods and follows previous administration tariffs on imported technology products.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Electronic Frontier Foundation and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science Security
Science Security

Preprint finds sensitive-topic leakage in AI model routing logs

Researchers report in a preprint that logs recording which AI model handles a request can expose sensitive-topic patterns even when content logging is disabled. Their studies used 1.7 million real requests and tested systems that ...

Security Infrastructure
Security Infrastructure

IDCF Cloud ransomware attack disrupts companies and local governments

A ransomware attack disrupted IDCF Cloud's East Japan Region 1 on October 7, affecting websites and services used by companies and local governments. A note article citing ITmedia and Nikkei reports said unauthorized access began ...

Security Infrastructure
Security Infrastructure

Registry breaches let attackers hijack domains and obtain HTTPS certificates

Attackers compromised third-party operators for Ghana's .GH, Sierra Leone's .SL and American Samoa's .AS domains, changed authoritative DNS records and obtained unauthorized HTTPS certificates, BleepingComputer reported. Google do...

Policy Infrastructure
Policy Infrastructure

Snowflake completes New Zealand Restricted security assessment on AWS

Snowflake says it has completed an independent third-party assessment of its deployment in the AWS Auckland region against New Zealand's Restricted-level security requirements. The assessment evaluated platform controls against re...

Security Infrastructure
Security Infrastructure

Researchers identify more than 3400 servers hit by PoeLLM mining malware

Lumen Black Lotus Labs identified more than 3400 victim servers in a cryptocurrency-mining campaign targeting exposed AI services and other enterprise systems, The Hacker News reported. The campaign, active since April 2026, insta...