{"id":5107,"date":"2025-08-24T16:08:36","date_gmt":"2025-08-24T16:08:36","guid":{"rendered":"https:\/\/areeblog.com\/?p=5107"},"modified":"2025-08-24T16:09:24","modified_gmt":"2025-08-24T16:09:24","slug":"sni5gect","status":"publish","type":"post","link":"https:\/\/areeblog.com\/sni5gect\/","title":{"rendered":"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities"},"content":{"rendered":"<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"5108\" data-permalink=\"https:\/\/areeblog.com\/sni5gect\/sni5gect-2\/\" data-orig-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg\" data-orig-size=\"1080,720\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Sni5Gect\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect-1024x683.jpg\" class=\"aligncenter size-full wp-image-5108\" src=\"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg\" alt=\"Sni5Gect: the 5G sniff-and-inject framework that changed the threat conversation\" width=\"1080\" height=\"720\" srcset=\"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg 1080w, https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect-300x200.jpg 300w, https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect-1024x683.jpg 1024w, https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect-768x512.jpg 768w, https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect-330x220.jpg 330w, https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect-420x280.jpg 420w, https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect-615x410.jpg 615w, https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect-860x573.jpg 860w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/><\/p>\n<p>When a team of researchers from the Singapore University of Technology and Design (SUTD) presented Sni5Gect at the 34th USENIX Security Symposium, they did more than publish an academic paper. They exposed a practical window in 5G New Radio (NR) behaviour where an attacker can observe ongoing protocol exchanges and, in some cases, inject spoofed messages that the handset will accept,\u00a0 all without running a rogue base station. That last detail removes a major logistical barrier to over-the-air attacks, and it forces a rethink of how we model risk at the very moment a device is trying to get on the <a href=\"https:\/\/areeblog.com\/understanding-packet-flow-in-computer-networking\/\">network<\/a>.<\/p>\n<p>Sni5Gect is a research framework: an engineered set of tools and techniques that can sniff control-plane messages in real time and craft downlink messages timed to the right protocol state so a User Equipment (UE) will accept them.<\/p>\n<p>The team released a public codebase and evaluation artifacts so other researchers and operators can reproduce, test, and defend against the techniques. That openness is important, it allows defenders to validate the threat, but it also raises the unavoidable trade-off between disclosure and potential misuse.<\/p>\n<h4><strong>Key takeaways<\/strong><\/h4>\n<ul>\n<li>Sni5Gect is a publicly disclosed research framework that can sniff 5G NR control-plane messages and inject timed downlink messages without a rogue base station.<\/li>\n<li>The framework exposes a vulnerable \u201cpre-authentication\u201d window in real-world 5G connections; attacks demonstrated include device crashes, fingerprinting, and multi-stage downgrades to 4G.<\/li>\n<li>Researchers achieved high success rates in controlled tests (sniffing accuracy often &gt;80\u201390%, injection success frequently 70\u201390% at short range), but practical reach and precision are limited by radio conditions and protocol constraints.<\/li>\n<li>SUTD released code, test data, and Docker images for reproducibility; the project is intended for research and defensive testing, and some dangerous exploit sequences were withheld from the public tree.<\/li>\n<li>Operators should treat this as a prompt to harden monitoring during the initial connection steps, accelerate relevant patching, and expand anomaly detection for unexpected downlink messages. GSMA has acknowledged the risk with a coordinated <a href=\"https:\/\/areeblog.com\/critical-vulnerability-in-alone-wordpress-theme-enables-widespread-site-takeovers\/\">vulnerability<\/a> disclosure identifier.<\/li>\n<\/ul>\n<h2>What is Sni5Gect?<\/h2>\n<p>Sni5Gect is a research toolkit that serializes two capabilities: (1) capturing live 5G NR control plane messages from the air and (2) sending crafted downlink control-plane messages that align with the timing and state expected by a target UE. The method relies on careful synchronization and state tracking so that an injected message looks legitimate when the handset receives it. That combination (passive observation followed by timely injection) is what makes the technique noteworthy.<\/p>\n<p>Historically, many practical over-the-air 5G attacks required a rogue gNodeB (a malicious base station). Running a rogue station is noisy, expensive, and easier to detect. Sni5Gect demonstrates that an attacker can accomplish some of the same objectives without pretending to be the network. That lowers the operational bar for certain attacks, making them potentially stealthier and more scalable in specific settings (for example, dense urban areas or near critical infrastructure).<\/p>\n<p>Importantly, Sni5Gect operates in the pre-authentication phase of the connection where some exchanges are still cleartext by design. Those unprotected exchanges are necessary for basic radio resource negotiation and service setup, but they also create a predictable surface that the framework exploits.<\/p>\n<h2>How Sni5Gect Framework Works (high level)<\/h2>\n<p>The Sni5Gect authors break the system into modular pieces that reflect the stages of a normal 5G exchange: synchronization, broadcast decoding, per-UE tracking, uplink\/downlink message processing, and downlink injection. That modular approach helps the software maintain the right protocol state for each tracked device and to time injected messages precisely. The public documentation and paper describe these components conceptually; the released artifacts include code and evaluation data for reproducibility.<\/p>\n<p>The framework\u2019s novelty is not a single trick but the orchestration: it combines radio synchronization and control-plane parsing with a <a href=\"https:\/\/areeblog.com\/contextual-anchoring-as-a-prompt-writing-technique\/\">message injection<\/a> engine that only speaks when the protocol state suggests the UE will accept a downlink message. Practically, that lets researchers demonstrate three categories of attacks: one-shot crashes or rejects, response-based fingerprinting where the tool elicits and observes a device response, and multi-stage downgrade sequences that push the UE to fallback to older, weaker technologies.<\/p>\n<p>The team evaluated Sni5Gect against multiple commercial devices and base station implementations in lab settings. They report high detection and injection rates at short distances, results that validate the concept without implying universal success under all field conditions. Radio propagation, interference, and vendor-specific protocol quirks still constrain practical performance.<\/p>\n<h2>What the Researchers Demonstrated (Attacks and Real-World Results)<\/h2>\n<p>The published work and accompanying reports describe several concrete outcomes that are useful for threat modeling:<\/p>\n<ul>\n<li><strong>Device crash and immediate downgrade:<\/strong> Injected messages timed to specific states triggered rejections or crashes on some handsets, which caused them to reconnect under weaker configurations. These are \u201cone-shot\u201d attacks that rely on precise timing.<\/li>\n<li><strong>Fingerprinting and identity harvesting:<\/strong> By injecting messages that provoke predictable responses, the framework can help an observer correlate protocol behavior to specific device models or subscribers, useful for tracking or reconnaissance.<\/li>\n<li><strong>Multi-stage downgrade (industry-acknowledged):<\/strong> The researchers disclosed a multi-stage downgrade attack that uses a crafted authentication sequence to induce handset behavior that prefers 4G. GSMA acknowledged the risk and assigned a coordinated vulnerability disclosure identifier. That underscores the industry relevance of the finding.<\/li>\n<\/ul>\n<p>Across lab tests, the authors reported sniffing accuracy often above 80\u201390% for certain message types and injection success commonly in the 70\u201390% range at short range. Those figures validate the concept but should not be read as a universal metric for all environments, distance, building materials, and competing radio signals materially affect real-world performance.<\/p>\n<h2>What Sni5Gect Cannot Do and Practical Limitations<\/h2>\n<p>While the publicity around Sni5Gect has been dramatic, the framework has clear limits that matter for defenders and risk assessments:<\/p>\n<ul>\n<li><strong>Not a universal remote control:<\/strong> The framework targets specific pre-authentication messages and timed windows. It cannot read or modify encrypted, post-authentication user traffic, so it is not a general purpose man-in-the-middle for arbitrary subscriber data.<\/li>\n<li><strong>Range and environment sensitive:<\/strong> Radio conditions matter. The reported success rates were measured in controlled setups and at modest distances. Urban clutter, managed spectrum, and base station power levels reduce the effective envelope for such techniques.<\/li>\n<li><strong>RNTI and protocol limits:<\/strong> Device tracking in the framework uses temporary identifiers and protocol state, which limits the attacker\u2019s ability to uniquely identify a subscriber long term without additional correlation data.<\/li>\n<li><strong>Responsible withholding:<\/strong> The research team deliberately withheld some exploit sequences from public release and framed the codebase for defensive testing and validation; that mitigates some, but not all, risk from public disclosure.<\/li>\n<\/ul>\n<p>These limitations don\u2019t make the project irrelevant, they simply frame the conditions where Sni5Gect is most potent: relatively close proximity, careful timing, and in scenarios where pre-authentication replies reveal useful state. For critical infrastructure or high-value targets in close quarters, those constraints are less comforting.<\/p>\n<h2>What Operators and Defenders Should Do<\/h2>\n<p>Sni5Gect is a concrete reminder that network security isn\u2019t only a matter of cryptography: it\u2019s also operational. Here are pragmatic steps teams can (and should) take.<\/p>\n<ol>\n<li><strong>Harden the initial connection visibility and monitoring.<\/strong> Instruments that monitor anomalous downlink control-plane messages especially during registration and, authentication windows, can detect injections or protocol anomalies early. Network operators should extend telemetry to those earlier stages and incorporate rules that flag odd timing patterns or messages from unexpected physical sectors.<\/li>\n<li><strong>Validate and patch baseband and core stacks.<\/strong> Vendor firmware and core network components sometimes include protocol fallbacks or behavioural quirks that Sni5Gect exploits. Work with vendors to prioritize patches for any vulnerabilities tied to pre-authentication handling. Where GSMA or vendor advisories exist, apply mitigations promptly.<\/li>\n<li><strong>Improve anomaly detection and correlation.<\/strong> Combine radio-layer anomalies with higher layer indicators (e.g., unexpected re-registrations, bursty authentication failures) so that localized sniff-and-inject attempts trigger operational responses. Correlating radio telemetry with subscriber behaviour reduces false positives and accelerates triage.<\/li>\n<li><strong>Limit attack surface where possible.<\/strong> Design network acceptance policies to require integrity checks before key transitions; where refinements to protocol state handling are possible, prefer patterns that reduce exploitable pre-auth windows. Industry bodies already discuss bidding-down and downgrade mitigations; operators should track and adopt those recommendations.<\/li>\n<li><strong>Use research releases defensively.<\/strong> The Sni5Gect codebase and dataset exist to help operators test real systems. Use those artifacts in controlled lab tests to validate local equipment behaviour and to tune IDS\/IPS rules, but only in regulated, legal test environments with proper authorization.<\/li>\n<\/ol>\n<h2>Ethics, Disclosure, and the Balance of Openness<\/h2>\n<p>The Sni5Gect story is also a case study in responsible research disclosure. The team published a paper and released tools but withheld a subset of potentially damaging exploit sequences. They coordinated with industry groups and documented the risk so operators could respond. That approach, publish enough to demonstrate a real threat and protect the community\u2019s ability to defend, while withholding the most dangerous weaponized exactly-repeatable recipes, is a defensible middle ground.<\/p>\n<p>Still, public releases of capability always carry risk. The net effect depends on how quickly operators patch, how well detection improves, and whether opportunistic adversaries can adapt the techniques to field constraints. That uncertainty is why GSMA and national regulators will take a renewed interest in pre-authentication robustness and why vendor timelines for firmware updates should receive scrutiny.<\/p>\n<h2>Research and Policy Implications<\/h2>\n<p>Sni5Gect is unlikely to be the last research project that surfaces a subtle but material attack path in 5G. The architecture of cellular systems, where radios negotiate capabilities, bandwidth, and identity before a secure channel is fully established, creates recurring design choices that trade convenience for exposure. The immediate policy implication is not to rip out functionality but to invest in layered defenses: better telemetry, more secure protocol defaults, and vendor practices that minimize pre-auth surprises.<\/p>\n<p>Sni5Gect is a useful, reproducible benchmark: it provides datasets, Docker images, and an open code base so that other teams can test mitigations, develop detection rules, or propose protocol improvements. It\u2019s also a call to treat pre-authentication behaviour as part of the attack surface, not as a benign implementation detail.<\/p>\n<h2>Closing Reframing<\/h2>\n<p>Sni5Gect doesn\u2019t break the promise of 5G; it clarifies the engineering tradeoffs that underlie that promise. The <a href=\"https:\/\/areeblog.com\/understanding-malware-threats-a-comprehensive-guide\/\">vulnerability window<\/a> it demonstrates is not some esoteric academic curiosity, it\u2019s an operational reality that can be exploited under certain conditions.<\/p>\n<p>The right response is proportionate: take the research seriously, test networks where possible, prioritize vendor fixes that address pre-authentication fragility, and build monitoring that covers the earliest moments of every connection. That combination reduces risk without undermining the benefits of mobile broadband.<\/p>\n<h2>References For Further Reading<\/h2>\n<ul>\n<li>Luo, S., Garbelini, M. E., Chattopadhyay, S., &amp; Zhou, J. \u201cSni5Gect: A Practical Approach to Inject aNRchy into 5G NR.\u201d <a href=\"https:\/\/www.usenix.org\/system\/files\/usenixsecurity25-luo-shijie.pdf\">USENIX Security 2025<\/a> (paper and PDF).<\/li>\n<li><a href=\"https:\/\/github.com\/asset-group\/Sni5Gect-5GNR-sniffing-and-exploitation\">Sni5Gect project repository<\/a> and public site (ASSET Research Group \/ GitHub).<\/li>\n<li>Zenodo: <a href=\"https:\/\/zenodo.org\/records\/15601773\">Sni5Gect dataset and Docker artifacts<\/a> for reproducibility.<\/li>\n<li>SecurityWeek coverage: \u201c<a href=\"https:\/\/www.securityweek.com\/novel-5g-attack-bypasses-need-for-malicious-base-station\/\">Novel 5G Attack Bypasses Need for Malicious Base Station<\/a>.\u201d<\/li>\n<li>The Register: \u201c<a href=\"https:\/\/www.theregister.com\/2025\/08\/18\/sni5gect\/\">Boffins release 5G traffic sniffing tool<\/a>\u201d (analysis and commentary).<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>When a team of researchers from the Singapore University of Technology and Design (SUTD) presented Sni5Gect at the 34th USENIX Security Symposium, they did more than publish an academic paper. They exposed a practical window in 5G New Radio (NR) behaviour where an attacker can observe ongoing protocol exchanges and, in some cases, inject spoofed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5108,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_monsterinsights_skip_tracking":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[14],"tags":[1036],"class_list":["post-5107","post","type-post","status-publish","format-standard","has-post-thumbnail","category-cybersecurity","tag-5g"],"share_on_mastodon":{"url":"","error":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities - Aree Blog<\/title>\n<meta name=\"description\" content=\"Sni5Gect reveals 5G security flaws by enabling real-time sniffing and injection attacks without rogue base stations.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/areeblog.com\/sni5gect\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities\" \/>\n<meta property=\"og:description\" content=\"Sni5Gect reveals 5G security flaws by enabling real-time sniffing and injection attacks without rogue base stations.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/areeblog.com\/sni5gect\/\" \/>\n<meta property=\"og:site_name\" content=\"Aree Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-24T16:08:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-08-24T16:09:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Daniel Chinonso John\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daniel Chinonso John\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/\"},\"author\":{\"name\":\"Daniel Chinonso John\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"headline\":\"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities\",\"datePublished\":\"2025-08-24T16:08:36+00:00\",\"dateModified\":\"2025-08-24T16:09:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/\"},\"wordCount\":1823,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/Sni5Gect.jpg\",\"keywords\":[\"5G\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/\",\"url\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/\",\"name\":\"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities - Aree Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/Sni5Gect.jpg\",\"datePublished\":\"2025-08-24T16:08:36+00:00\",\"dateModified\":\"2025-08-24T16:09:24+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"description\":\"Sni5Gect reveals 5G security flaws by enabling real-time sniffing and injection attacks without rogue base stations.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/#primaryimage\",\"url\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/Sni5Gect.jpg\",\"contentUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/Sni5Gect.jpg\",\"width\":1080,\"height\":720,\"caption\":\"Sni5Gect: the 5G sniff-and-inject framework that changed the threat conversation\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/sni5gect\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/areeblog.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\",\"url\":\"https:\\\/\\\/areeblog.com\\\/\",\"name\":\"Aree Blog\",\"description\":\"Unfiltered Perspectives, Unstoppable Insights\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/areeblog.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\",\"name\":\"Daniel Chinonso John\",\"description\":\"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/daniel-john-45183a169\\\/\"],\"url\":\"https:\\\/\\\/areeblog.com\\\/author\\\/danojohn55gmail-com\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities - Aree Blog","description":"Sni5Gect reveals 5G security flaws by enabling real-time sniffing and injection attacks without rogue base stations.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/areeblog.com\/sni5gect\/","og_locale":"en_US","og_type":"article","og_title":"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities","og_description":"Sni5Gect reveals 5G security flaws by enabling real-time sniffing and injection attacks without rogue base stations.","og_url":"https:\/\/areeblog.com\/sni5gect\/","og_site_name":"Aree Blog","article_published_time":"2025-08-24T16:08:36+00:00","article_modified_time":"2025-08-24T16:09:24+00:00","og_image":[{"width":1080,"height":720,"url":"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg","type":"image\/jpeg"}],"author":"Daniel Chinonso John","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Daniel Chinonso John","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/areeblog.com\/sni5gect\/#article","isPartOf":{"@id":"https:\/\/areeblog.com\/sni5gect\/"},"author":{"name":"Daniel Chinonso John","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"headline":"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities","datePublished":"2025-08-24T16:08:36+00:00","dateModified":"2025-08-24T16:09:24+00:00","mainEntityOfPage":{"@id":"https:\/\/areeblog.com\/sni5gect\/"},"wordCount":1823,"commentCount":0,"image":{"@id":"https:\/\/areeblog.com\/sni5gect\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg","keywords":["5G"],"articleSection":["Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/areeblog.com\/sni5gect\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/areeblog.com\/sni5gect\/","url":"https:\/\/areeblog.com\/sni5gect\/","name":"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities - Aree Blog","isPartOf":{"@id":"https:\/\/areeblog.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/areeblog.com\/sni5gect\/#primaryimage"},"image":{"@id":"https:\/\/areeblog.com\/sni5gect\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg","datePublished":"2025-08-24T16:08:36+00:00","dateModified":"2025-08-24T16:09:24+00:00","author":{"@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"description":"Sni5Gect reveals 5G security flaws by enabling real-time sniffing and injection attacks without rogue base stations.","breadcrumb":{"@id":"https:\/\/areeblog.com\/sni5gect\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/areeblog.com\/sni5gect\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/areeblog.com\/sni5gect\/#primaryimage","url":"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg","contentUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg","width":1080,"height":720,"caption":"Sni5Gect: the 5G sniff-and-inject framework that changed the threat conversation"},{"@type":"BreadcrumbList","@id":"https:\/\/areeblog.com\/sni5gect\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/areeblog.com\/"},{"@type":"ListItem","position":2,"name":"Sni5Gect: A New Framework Revealing Hidden 5G Vulnerabilities"}]},{"@type":"WebSite","@id":"https:\/\/areeblog.com\/#website","url":"https:\/\/areeblog.com\/","name":"Aree Blog","description":"Unfiltered Perspectives, Unstoppable Insights","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/areeblog.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63","name":"Daniel Chinonso John","description":"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.","sameAs":["https:\/\/www.linkedin.com\/in\/daniel-john-45183a169\/"],"url":"https:\/\/areeblog.com\/author\/danojohn55gmail-com\/"}]}},"jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":6553,"url":"https:\/\/areeblog.com\/vietnam-puts-ai-infrastructure-and-digital-assets-at-the-heart-of-its-digital-economy-push\/","url_meta":{"origin":5107,"position":0},"title":"Vietnam Puts AI Infrastructure and Digital Assets at the Heart of Its Digital-Economy Push","author":"Daniel Chinonso John","date":"August 16, 2026","format":false,"excerpt":"Vietnam is expanding its digital-economy strategy around data, artificial intelligence infrastructure and regulated digital assets, with new national targets for computing capacity arriving as the country develops a framework for tokenized assets. The government approved a National Digital Economy and Digital Society Development Program for 2026\u20132030 in June, setting a\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Vietnam Puts AI Infrastructure and Digital Assets at the Heart of Its Digital-Economy Push","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/vietnam-pushes-for-homegrown-ai-infrastructure-to-fuel-digital-growth-04f838950bce44c3a92c525418cf10f4-3259.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/vietnam-pushes-for-homegrown-ai-infrastructure-to-fuel-digital-growth-04f838950bce44c3a92c525418cf10f4-3259.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/vietnam-pushes-for-homegrown-ai-infrastructure-to-fuel-digital-growth-04f838950bce44c3a92c525418cf10f4-3259.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/vietnam-pushes-for-homegrown-ai-infrastructure-to-fuel-digital-growth-04f838950bce44c3a92c525418cf10f4-3259.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/vietnam-pushes-for-homegrown-ai-infrastructure-to-fuel-digital-growth-04f838950bce44c3a92c525418cf10f4-3259.jpg?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/vietnam-pushes-for-homegrown-ai-infrastructure-to-fuel-digital-growth-04f838950bce44c3a92c525418cf10f4-3259.jpg?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":5494,"url":"https:\/\/areeblog.com\/mea-consumer-tech-market-update\/","url_meta":{"origin":5107,"position":1},"title":"MEA Consumer Tech Market Update","author":"Samuel Ogori","date":"October 6, 2025","format":false,"excerpt":"The MEA consumer tech market is moving from volume-driven growth to a more diverse landscape. Cheap, durable devices now share shelf space with premium smartphones and smart home gadgets, marking a quiet but meaningful transition in how people across the region experience technology. Over the past two years, the Middle\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"MEA Consumer Tech Market Update","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/10\/Mea-consumer-tech.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/10\/Mea-consumer-tech.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/10\/Mea-consumer-tech.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/10\/Mea-consumer-tech.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/10\/Mea-consumer-tech.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6503,"url":"https:\/\/areeblog.com\/coinbases-abu-dhabi-move-signals-the-next-phase-of-institutional-tokenization\/","url_meta":{"origin":5107,"position":2},"title":"Coinbase\u2019s Abu Dhabi Move Signals the Next Phase of Institutional Tokenization","author":"Daniel Chinonso John","date":"August 13, 2026","format":false,"excerpt":"Coinbase has established an international tokenization hub in Abu Dhabi after receiving Financial Services Permission from the Financial Services Regulatory Authority (FSRA) of Abu Dhabi Global Market (ADGM), giving the cryptocurrency company regulatory approval to arrange investment deals and provide custody as it prepares to launch tokenized securities. Coinbase announced\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Coinbase\u2019s Abu Dhabi Move Signals the Next Phase of Institutional Tokenization","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-32.jpeg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-32.jpeg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-32.jpeg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-32.jpeg?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":6755,"url":"https:\/\/areeblog.com\/next-js-canary-adds-controls-for-server-actions-and-ai-apps\/","url_meta":{"origin":5107,"position":3},"title":"Next.js Canary Adds Controls for Server Actions and AI Apps","author":"Daniel Chinonso John","date":"September 4, 2026","format":false,"excerpt":"Next.js is refining how its framework handles Server Action requests in its latest Canary release, introducing clearer HTTP responses for malformed action references and valid references that are no longer available in a deployment. The change was included in Next.js v16.4.0-canary.16, published on September 3, 2026. The release is a\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Next.js Canary Adds Controls for Server Actions and AI Apps","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/9c74ea42029a229829f2e06b039f4fb477938c83-2400x1350_Z2wmccV.webp?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/9c74ea42029a229829f2e06b039f4fb477938c83-2400x1350_Z2wmccV.webp?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/9c74ea42029a229829f2e06b039f4fb477938c83-2400x1350_Z2wmccV.webp?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/9c74ea42029a229829f2e06b039f4fb477938c83-2400x1350_Z2wmccV.webp?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/9c74ea42029a229829f2e06b039f4fb477938c83-2400x1350_Z2wmccV.webp?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6326,"url":"https:\/\/areeblog.com\/the-white-house-launches-ai-cybersecurity-coordination-group\/","url_meta":{"origin":5107,"position":4},"title":"The White House Launches AI Cybersecurity Coordination Group","author":"Daniel Chinonso John","date":"July 15, 2026","format":false,"excerpt":"The White House has unveiled a new initiative designed to bring artificial intelligence developers and operators of critical infrastructure together in a coordinated effort to identify and address software vulnerabilities before they can be exploited. The move marks a significant step in the U.S. government's evolving approach to cybersecurity, positioning\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"The White House Launches AI Cybersecurity Coordination Group","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/gettyimages-2285235825.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/gettyimages-2285235825.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/gettyimages-2285235825.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/gettyimages-2285235825.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/gettyimages-2285235825.jpg?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/gettyimages-2285235825.jpg?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":6839,"url":"https:\/\/areeblog.com\/google-says-hackers-are-using-ai-agents-to-run-multi-stage-attacks-with-little-human-input\/","url_meta":{"origin":5107,"position":5},"title":"Google Says Hackers Are Using AI Agents to Run Multi-Stage Attacks With Little Human Input","author":"Daniel Chinonso John","date":"September 9, 2026","format":false,"excerpt":"Hackers are increasingly using artificial intelligence to automate multiple stages of cyberattacks, with Google Threat Intelligence Group reporting that some attackers have moved beyond simple prompting to AI-driven workflows capable of scanning targets, troubleshooting failures and harvesting credentials with limited human involvement. In a report published September 8, 2026, Google\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Google Says Hackers Are Using AI Agents to Run Multi-Stage Attacks With Little Human Input","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-55.jpeg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-55.jpeg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-55.jpeg?resize=525%2C300&ssl=1 1.5x"},"classes":[]}],"jetpack_featured_media_url":"https:\/\/areeblog.com\/wp-content\/uploads\/2025\/08\/Sni5Gect.jpg","_links":{"self":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/5107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/comments?post=5107"}],"version-history":[{"count":0,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/5107\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media\/5108"}],"wp:attachment":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media?parent=5107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/categories?post=5107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/tags?post=5107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}