Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
AT&T CISO Rich Baich said at the September 2025 Google Cloud Cyber Defense Summit that he was seeing adversaries change their methods in ways similar to Salt Typhoon. The behaviors he described target gaps in endpoint monitoring and logging, and misuse administrative tools that defenders already rely on. His remarks, reported by CyberScoop, are an executive’s assessment—not independent proof that specific groups copied Salt Typhoon.
What Baich said was changing
Baich’s warning was about how attackers operate, not a list of named groups confirmed to have imitated Salt Typhoon. CyberScoop reported on September 22, 2025, that Baich said he was seeing adversaries change their methods “very similar to what Salt Typhoon did.” The account did not identify those adversaries or provide separate incident evidence establishing who adopted each behavior.
The report describes three areas of concern: systems with less endpoint monitoring, places where logs or expected controls are missing, and the use of legitimate administrative tools to blend into routine activity. It also notes Baich’s concern that attackers may cover or wipe tracks, complicating digital forensics.
Three techniques defenders should understand
1. Target platforms outside standard EDR coverage
Endpoint detection and response (EDR) is not necessarily deployed across every device or platform in an organization. Baich said attackers were looking for platforms that traditionally lacked EDR, shifting attention beyond conventional, well-monitored endpoints. The defensive question is whether important systems and devices fall outside the organization’s endpoint-protection coverage.
#1 Best Overall
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
2. Look for places without logs or enabled controls
Baich described attackers seeking systems or network areas where logs were unavailable or expected controls had not been enabled. In his account, that makes gaps in visibility a potential advantage for an intruder: activity in an unlogged area is harder to detect and reconstruct. He described the search for missing logs as a technique growing in use since the Salt Typhoon attacks; the report does not quantify how widespread it is.
3. Use the victim’s own administrative tools
Attackers can use legitimate tools that administrators already use to manage systems and networks. Those tools have valid operational purposes, so their presence alone does not establish malicious activity. But if defenders do not know which tools are available, who can use them, or what normal use looks like, suspicious activity can blend into routine administration.
Rank #2
- Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
- FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
- Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
- Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
- Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.
What organizations can check
Baich’s recommendations point to practical coverage and control checks, rather than a single product or fix:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute- Review endpoint coverage: Identify platforms and devices without EDR, then assess whether additional endpoint protection is appropriate for them.
- Map logging gaps: Check where logs are generated, whether they are retained, and which network areas lack expected logging or security controls.
- Inventory administrative tools: Know which tools are present, what legitimate work they support, and who is authorized to use them. Restrict access and use where appropriate.
- Consider forensic visibility: Evaluate whether available records would let investigators reconstruct activity if an attacker attempted to cover or wipe tracks.
These checks address different failure points. More endpoint coverage does not fill a logging gap; more logs do not by themselves restrict powerful administrative tools. Defenders need to understand how their technology is used operationally and how an intruder could misuse that same environment.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
What the warning does—and does not—establish
CyberScoop reported that AT&T had been among the major providers affected by Salt Typhoon and had said it evicted the hackers from its networks. The article gives no technical account, date, or scope for that eviction. It also does not establish how common the described techniques were across the wider threat landscape or demonstrate that particular groups copied Salt Typhoon.
Accordingly, “inspiring” should be read as Baich’s characterization of similar changes in adversary behavior, not as a verified chain of imitation. His broader point was that organizations need to understand both how their technology works and how it could be used against them.
Quick Recap
Rank #4
- Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
- NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
- FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
- Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
- Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

