Validated Containment Architectures are here. →Explore

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

794 threat reports
Page 1 of 67

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Telecommunications Threat Reports

Showing 112 / 794 reports
Urgent: Patch Critical Vulnerability in Progress Kemp LoadMaster Now
Impact· CRITICAL

Urgent: Patch Critical Vulnerability in Progress Kemp LoadMaster Now

In June 2026, a critical vulnerability (CVE-2026-8037) was identified in Progress Kemp LoadMaster appliances, allowing unauthenticated attackers to execute arbitrary commands remotely. This command injection flaw, present in the 'escape_quotes()' function, enables attackers to gain root access without valid credentials. ([hackerposts.org](https://www.hackerposts.org/en/blog/progress-kemp-loadmaster-cve-2026-8037-preauth-rce?utm_source=openai)) Exploitation attempts began on June 29, 2026, following the public release of a proof-of-concept exploit. ([esentire.com](https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037?utm_source=openai)) The inclusion of this vulnerability in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to apply the necessary patches promptly to mitigate potential threats. ([aha.org](https://www.aha.org/h-isac-white-reports/2026-07-01-h-isac-tlp-white-threat-bulletin-observed-exploitation-attempts-targeting-critical-progress?utm_source=openai))

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Highlights Critical Vulnerability in Progress LoadMaster: CVE-2026-8037
Impact· CRITICAL

CISA Highlights Critical Vulnerability in Progress LoadMaster: CVE-2026-8037

In August 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting active exploitation of this critical command injection vulnerability in Progress Software's LoadMaster appliance. This flaw allows unauthenticated attackers to execute arbitrary commands via unsanitized input in multiple API endpoints, potentially leading to full system compromise. Organizations utilizing affected versions are urged to apply patches immediately to mitigate the risk of unauthorized access and data breaches. The inclusion of CVE-2026-8037 in the KEV Catalog underscores the persistent threat posed by command injection vulnerabilities, which remain a favored attack vector for cyber adversaries. This incident serves as a critical reminder for organizations to prioritize timely remediation of known vulnerabilities and to implement robust input validation mechanisms to prevent similar exploits.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
NatJack Attack: Exploiting NAT Vulnerabilities in Windows and Linux
Impact· HIGH

NatJack Attack: Exploiting NAT Vulnerabilities in Windows and Linux

In August 2026, security researcher Malcolm Stagg unveiled 'NatJack,' a novel attack class that exploits vulnerabilities in Network Address Translation (NAT) implementations to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. The research identified two critical vulnerabilities: CVE-2026-56181 in Windows NAT used by Hyper-V and CVE-2026-63913 in Linux Netfilter conntrack. These flaws allow attackers with privileged access to a system behind the same NAT as the victim to manipulate connection states, leading to potential data interception and service disruptions. Organizations are advised to apply the latest patches and implement network segmentation to mitigate these risks. The NatJack disclosure underscores the evolving threat landscape targeting network infrastructure. As attackers continue to find and exploit design assumptions in widely used technologies, it is imperative for organizations to reassess their network security postures, prioritize internal traffic encryption, and adopt zero-trust principles to safeguard against such sophisticated attacks.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Linux Kernel Vulnerability (CVE-2026-64564) Exposes Systems to Root Access and Container Escapes
Impact· HIGH

Critical Linux Kernel Vulnerability (CVE-2026-64564) Exposes Systems to Root Access and Container Escapes

An 18-year-old use-after-free vulnerability in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation, identified as CVE-2026-64564 and dubbed 'SCTPhantom,' has been discovered. This flaw allows local users to escalate privileges to root and potentially escape containerized environments. The vulnerability has existed since 2008 and affects all kernel versions from 2.6.25 onwards. Tencent's Zhuque Lab demonstrated successful exploitation on distributions including Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, and OpenCloudOS. The issue arises from improper handling of delete requests in SCTP's dynamic address reconfiguration feature, leading to use-after-free conditions. The vulnerability was publicly disclosed on August 6, 2026, with patches released in stable kernel versions 7.1.6, 6.18.42, 6.12.101, and 6.6.148 on August 3, 2026. Organizations are urged to update their systems promptly to mitigate potential exploitation risks.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Canadian Hacker Convicted in Massive Snowflake Data Breach Extortions
Impact· CRITICAL

Canadian Hacker Convicted in Massive Snowflake Data Breach Extortions

Between February and October 2024, Connor Riley Moucka, a 26-year-old Canadian, orchestrated unauthorized access to at least 165 organizations utilizing Snowflake's cloud data services. Exploiting stolen credentials from accounts lacking multi-factor authentication, Moucka and his co-conspirators exfiltrated sensitive data, including personal information and call records of over 100 million AT&T customers. The stolen data was used to extort victims by threatening public disclosure. This incident underscores the critical importance of implementing robust security measures, such as multi-factor authentication, to protect cloud-based data. Organizations must remain vigilant against credential-based attacks, as threat actors continue to exploit such vulnerabilities for financial gain and data theft.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
15 TP-Link Vulnerabilities Unveil Critical Zero-Touch Provisioning Risks
Impact· CRITICAL

15 TP-Link Vulnerabilities Unveil Critical Zero-Touch Provisioning Risks

In August 2026, researchers at Black Hat USA disclosed 15 vulnerabilities in TP-Link's Omada software-defined networking ecosystem, highlighting significant security risks associated with zero-touch provisioning (ZTP). These vulnerabilities, affecting routers, switches, gateways, and Wi-Fi access points, could be exploited to hijack devices, execute client-side code, disclose sensitive information, and compromise encryption protocols. The findings underscore the potential for large-scale network intrusions facilitated by automated provisioning processes. The incident serves as a critical reminder of the inherent risks in ZTP implementations, emphasizing the need for organizations to scrutinize and secure their provisioning workflows. As ZTP adoption grows, ensuring robust security measures during device onboarding becomes paramount to prevent exploitation by threat actors.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Snowflake Data Breach: Lessons in Credential Security
Impact· CRITICAL

Snowflake Data Breach: Lessons in Credential Security

In 2024, threat actor UNC5537 exploited stolen credentials to access Snowflake customer accounts lacking multi-factor authentication (MFA), compromising at least 165 organizations and exposing data of over 100 million individuals. The attackers utilized infostealer malware to harvest credentials, some dating back to 2020, leading to significant data breaches affecting companies like AT&T and Ticketmaster. This incident underscores the critical importance of implementing robust security measures, such as MFA and regular credential rotation, to protect against credential-based attacks. Organizations must remain vigilant as similar tactics continue to pose significant threats to data security.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Backdoor Found in Zbtlink Routers: 'ENDLESSDOORS' Exposes Networks to Remote Exploitation
Impact· HIGH

Critical Backdoor Found in Zbtlink Routers: 'ENDLESSDOORS' Exposes Networks to Remote Exploitation

In August 2026, cybersecurity researchers uncovered a factory-implanted backdoor, dubbed 'ENDLESSDOORS,' in at least 20 router models from Chinese manufacturer Zbtlink. This backdoor, present in all 21 firmware images available over the past two years, automatically initiates and attempts to communicate with command-and-control servers every 35 seconds. Masquerading as legitimate Linux kernel threads, these userland processes run with root privileges, allowing unauthorized remote control of the devices. The backdoor utilizes a tool called 'rctl' to establish connections without authentication, enabling attackers to execute arbitrary commands or spawn interactive root shells remotely. The affected models include CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and Z8102AX-2DSIM. This discovery underscores the critical risks associated with supply chain vulnerabilities in networking hardware, particularly those manufactured overseas. The incident has prompted heightened scrutiny of foreign-made networking equipment and reinforces the importance of rigorous security assessments in the procurement process.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Over 4,400 Rockwell PLCs Exposed Online: A Wake-Up Call for Critical Infrastructure Security
Impact· CRITICAL

Over 4,400 Rockwell PLCs Exposed Online: A Wake-Up Call for Critical Infrastructure Security

In August 2026, Forescout identified 4,407 internet-exposed Rockwell Automation programmable logic controllers (PLCs) worldwide, with 2,844 located in the United States. Notably, 22 of these exposed PLCs were found in cities recently targeted by cyberattacks on U.S. water utilities, with 19 utilizing the same mobile carrier network. Attackers exploited these vulnerabilities by altering IP addresses and setting passwords on accessible controllers, leading to operators losing visibility and control over connected equipment. This incident underscores the critical need for securing industrial control systems against unauthorized internet exposure. The prevalence of internet-exposed PLCs highlights a significant security gap in critical infrastructure, particularly within the water sector. The ease with which attackers can manipulate these systems without exploiting specific vulnerabilities emphasizes the urgency for organizations to implement robust network segmentation, remove unnecessary internet exposure, and enforce strong authentication measures to protect against potential disruptions and threats to public safety.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Snowflake 2024 Data Breach: A Wake-Up Call for Cloud Security
Impact· MEDIUM

Snowflake 2024 Data Breach: A Wake-Up Call for Cloud Security

In mid-2024, a significant cybersecurity incident unfolded involving unauthorized access to over 165 customer environments hosted on Snowflake Inc.'s cloud platform. Threat actors, notably including Connor Moucka, exploited stolen credentials—often lacking multi-factor authentication—to infiltrate these environments. High-profile victims such as AT&T, Ticketmaster, and Santander Bank suffered extensive data theft, leading to substantial financial losses and reputational damage. The attackers utilized the stolen data for extortion, demanding ransoms to prevent public disclosure. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Snowflake_data_breach?utm_source=openai)) This breach underscores the critical importance of robust access controls and the implementation of multi-factor authentication (MFA) in cloud environments. The incident serves as a stark reminder of the vulnerabilities associated with single-factor authentication and the necessity for organizations to enforce stringent security measures to protect sensitive data. ([techtarget.com](https://www.techtarget.com/searchsecurity/news/366587555/Snowflake-No-evidence-of-platform-breach?utm_source=openai))

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Snowflake Data Breach 2024: A Wake-Up Call for Cloud Security
Impact· CRITICAL

Snowflake Data Breach 2024: A Wake-Up Call for Cloud Security

Between February and October 2024, cybercriminals exploited stolen credentials to access Snowflake customer accounts lacking multi-factor authentication (MFA). This led to unauthorized access to sensitive data from at least 165 organizations, including AT&T, Ticketmaster, and Santander. The attackers, notably Connor Riley Moucka and John Erin Binns, utilized infostealer malware to harvest login information, resulting in the theft of terabytes of data and extortion of millions of dollars from affected companies. The incident underscores the critical importance of implementing robust security measures, such as MFA, to protect cloud-based data. As cloud services become increasingly integral to business operations, organizations must prioritize stringent access controls and continuous monitoring to mitigate the risk of similar breaches.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
OpenAI's Intervention in Poipet Scam Network Exploiting ChatGPT
Impact· MEDIUM

OpenAI's Intervention in Poipet Scam Network Exploiting ChatGPT

In August 2026, OpenAI identified and dismantled a sophisticated scam network operating from Poipet, Cambodia, that exploited its ChatGPT technology to orchestrate various fraudulent schemes, including investment scams, romance frauds, gambling cons, and law enforcement impersonations. The perpetrators utilized ChatGPT to create fake online personas, generate and translate deceptive messages, and produce promotional content targeting victims primarily in Bangladesh and India. This operation highlights the evolving misuse of AI tools in cybercrime, enabling scammers to scale their activities and enhance the credibility of their deceptive practices. The incident underscores the urgent need for robust AI governance and proactive measures to prevent the exploitation of generative AI technologies in fraudulent activities.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports