✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
UAC-0145's Use of ClickFix CAPTCHAs: A New Cyber Threat in Ukraine
In July 2026, the Russian state-sponsored hacking group UAC-0145, also known as Sandworm or APT44, launched a campaign targeting Ukrainian organizations. The attackers employed a technique called ClickFix, which involves fake CAPTCHA prompts on compromised websites. These prompts instructed users to execute PowerShell commands, leading to the installation of data-stealing malware such as GHETTOVIBE and SCOUTCURL. The campaign compromised at least ten websites and utilized tools like SMARTAXE to dynamically alter web content, displaying deceptive CAPTCHA checks. Additionally, the attackers distributed malicious Android APK files via messaging apps, deploying the COWARDDUCK backdoor to exfiltrate sensitive information from infected devices. This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly adopting social engineering techniques traditionally associated with financially motivated cybercriminals. The use of ClickFix by UAC-0145 highlights the need for heightened vigilance and user education to recognize and avoid such deceptive tactics.
1 day ago
Kill Chain
OpenSSL HollowByte Flaw: Critical DoS Vulnerability Discovered
In July 2026, a vulnerability named 'HollowByte' was discovered in OpenSSL, allowing unauthenticated attackers to trigger a denial-of-service (DoS) condition on servers by sending a malicious 11-byte payload. This flaw causes the server to allocate significant memory for a message that never arrives, leading to potential service disruptions. The OpenSSL team has silently patched this vulnerability without assigning a CVE identifier or issuing an advisory. Organizations relying on OpenSSL for secure communications should prioritize updating to the latest patched versions to mitigate this risk. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/?utm_source=openai)) The HollowByte vulnerability underscores the critical importance of timely patch management and the need for organizations to stay vigilant about silent fixes in widely used libraries. As cyber threats continue to evolve, ensuring that foundational security components like OpenSSL are up-to-date is essential to maintain robust defense mechanisms.
3 days ago
Kill Chain
Salt Typhoon Cyberattack 2024: A Wake-Up Call for Surveillance System Security
In October 2024, the Salt Typhoon cyberattack, allegedly backed by China, targeted U.S. wiretap systems, granting attackers access to sensitive intelligence and law enforcement communications collected by major U.S. internet service providers such as Verizon, AT&T, and Lumen Technologies. The breach exploited systems designed for lawful surveillance, highlighting vulnerabilities in government-mandated surveillance infrastructure. This incident underscores the critical need for robust cybersecurity measures to protect sensitive communication channels from state-sponsored cyber espionage. The Salt Typhoon attack is part of a broader pattern of advanced persistent threats linked to Beijing, raising significant national security concerns regarding foreign access to critical U.S. surveillance infrastructure.
3 days ago
Kill Chain
Russian Hackers Exploit WebEx and Zoom Installers to Deploy Starland RAT
In June 2025, the Russian threat actor UAT-11795 initiated a campaign targeting users primarily in the United States, with additional victims in Germany, Romania, and Venezuela. The attackers distributed trojanized installers of legitimate software, including WebEx and Zoom, to deploy the Starland RAT malware. This backdoor enabled the exfiltration of browser data, cryptocurrency wallet assets, system details, and Active Directory information. The malware also facilitated remote command execution, screenshot capture, and the deployment of additional payloads such as CastleStealer and Remcos RAT. This incident underscores the increasing sophistication of supply chain attacks, where trusted software is weaponized to infiltrate systems. The use of trojanized installers highlights the critical need for organizations to enforce strict software sourcing policies and to educate users on the risks of downloading software from unofficial sources.
4 days ago
Kill Chain
Daxin and Stupig Malware Resurface in Taiwan Manufacturing Firm
In May 2026, Symantec's Threat Hunter Team identified the re-emergence of Backdoor.Daxin, a sophisticated kernel-mode rootkit previously linked to China-based threat actors, on a compromised host within a Taiwan-based subsidiary of a multinational high-tech manufacturer. Alongside Daxin, researchers discovered a novel backdoor named Stupig, which exploits a trojanized keyboard-layout DLL to execute commands with SYSTEM privileges directly from the Windows logon screen, bypassing standard authentication mechanisms. Both malware samples carry compile timestamps from early 2013, suggesting a prolonged undetected presence of up to 13 years within the victim's network. This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure and high-tech industries. The discovery of Stupig's unique pre-authentication execution method highlights the need for continuous vigilance and advanced detection capabilities to identify and mitigate such stealthy intrusions.
4 days ago
Kill Chain
US Indicts Russian Nationals for Bulletproof Hosting Services in 2026
In July 2026, U.S. federal prosecutors unsealed charges against three Russian nationals—Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin—for operating bulletproof hosting services, Media Land and ML.Cloud. These services provided infrastructure to ransomware gangs, facilitating over $62 million in damages globally. The hosting services were designed to resist law enforcement takedown efforts, supporting activities such as malware distribution, command-and-control operations, and phishing attacks. The infrastructure spanned multiple countries, including China, Finland, the Netherlands, and the United States. This incident underscores the persistent threat posed by bulletproof hosting services in the cybercrime ecosystem. The U.S. Department of State has offered a $10 million reward for information on these individuals, highlighting the international commitment to dismantling such networks. Organizations are urged to enhance their cybersecurity measures to mitigate risks associated with these resilient infrastructures.
5 days ago
Kill Chain
Dutch Authorities Dismantle €100 Million Investment Fraud Network
In July 2026, Dutch authorities dismantled a sophisticated international investment fraud scheme that operated 20 call centers across multiple countries, employing over 700 individuals posing as financial advisors. The organization is estimated to have defrauded tens of thousands of victims, amassing over €100 million per month at its peak. The fraudsters built trust with victims over extended periods, introducing them to realistic-looking investment platforms that displayed fictitious profits. Victims were persuaded to increase their investments, often through cryptocurrency transfers, while the criminals siphoned the funds and presented fake dashboards showing inflated returns. This incident underscores the evolving complexity and scale of cyber-enabled financial fraud, highlighting the need for enhanced vigilance and regulatory measures in the financial sector. The use of sophisticated social engineering tactics and the exploitation of cryptocurrency platforms for illicit gains reflect broader trends in cybercrime, necessitating continuous adaptation of security strategies by organizations and individuals alike.
5 days ago
Kill Chain
TuxBot v3 Evolution: Unveiling the AI-Assisted IoT Botnet Threat
In early 2026, cybersecurity researchers uncovered TuxBot v3 Evolution, a sophisticated modular IoT botnet framework. This malware targets a wide range of IoT devices by exploiting known vulnerabilities and employing extensive Telnet brute-force attacks. Notably, the development of TuxBot v3 Evolution involved assistance from a large language model (LLM), resulting in both functional components and critical errors due to unreviewed AI-generated code. The botnet's capabilities include multi-architecture support, encrypted command-and-control communications, and a variety of fallback mechanisms, posing a significant threat to IoT security. The discovery of TuxBot v3 Evolution underscores the evolving landscape of cyber threats, where adversaries leverage AI technologies to enhance malware development. This trend highlights the urgent need for robust security measures and continuous monitoring to protect IoT ecosystems from increasingly sophisticated attacks.
5 days ago
Kill Chain
Critical Vulnerabilities in 6 GHz Wi-Fi AFC Systems Uncovered
In July 2026, researchers from Pennsylvania State University and Idaho National Laboratory identified significant security vulnerabilities in Automated Frequency Coordination (AFC) systems, which manage the 6 GHz Wi-Fi spectrum to prevent interference with critical infrastructure. The study revealed that AFC systems inherently trust client-side data, such as GPS coordinates and time synchronization inputs, without adequate verification. This trust model exposes the systems to potential attacks where adversaries could spoof location data or manipulate time synchronization, leading to unauthorized spectrum access, harmful interference with incumbent services, or denial-of-service conditions for legitimate 6 GHz Wi-Fi users. ([darkreading.com](https://www.darkreading.com/perimeter/6-ghz-wi-fi-flaws-disrupt-critical-systems?utm_source=openai)) The findings underscore the urgent need for enhanced security measures in AFC systems, especially as the adoption of 6 GHz Wi-Fi expands. Without addressing these vulnerabilities, critical communication infrastructures remain at risk of disruption, highlighting the importance of implementing robust authentication and validation mechanisms within AFC architectures to safeguard against potential exploits.
5 days ago
Kill Chain
Unveiling TuxBot v3 Evolution: The AI-Assisted IoT Botnet Threat
In early 2026, security researchers identified TuxBot v3 Evolution, a sophisticated modular IoT botnet framework. This malware targets a wide range of IoT devices by exploiting known vulnerabilities and employing extensive Telnet brute-force attacks. Notably, the developers utilized large language models (LLMs) to assist in code development, resulting in a mix of functional and flawed components. The botnet's capabilities include cross-compilation for multiple architectures, encrypted command-and-control (C2) communications, and a DDoS-for-hire panel. Despite some non-functional features due to development oversights, the framework's modularity and adaptability pose a significant threat to IoT security. The emergence of TuxBot v3 Evolution underscores a concerning trend: the integration of AI tools in malware development, which can accelerate the creation of complex and adaptable threats. This incident highlights the urgent need for enhanced security measures in IoT devices and the importance of monitoring AI-assisted developments in the cyber threat landscape.
5 days ago
Kill Chain
Strengthening Router Security Against State-Sponsored Cyber Threats
In July 2026, a joint advisory from the NSA, CISA, FBI, and international partners highlighted that Russian FSB Center 16 cyber actors, also known as Berserk Bear and Dragonfly, have been exploiting poorly configured and vulnerable networking devices worldwide. These actors primarily target critical infrastructure sectors such as communications, energy, defense, financial services, government facilities, and healthcare. Their tactics include scanning for devices with default or weak SNMP credentials and exploiting known vulnerabilities in Cisco devices and protocols, enabling unauthorized access and potential disruption of essential services. This incident underscores the persistent threat posed by state-sponsored cyber actors targeting critical infrastructure through common vulnerabilities. Organizations are urged to enhance their network security by updating device configurations, disabling legacy protocols, and implementing strong authentication measures to mitigate such risks.
6 days ago
Kill Chain
CISA Adds CVE-2008-4128 to Known Exploited Vulnerabilities Catalog
On July 13, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2008-4128 to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability, a Cross-Site Request Forgery (CSRF) flaw in the HTTP Administration component of Cisco IOS 12.4 running on 871 Integrated Services Routers, allows remote attackers to execute arbitrary commands. Despite being disclosed in 2008, recent evidence indicates active exploitation, prompting CISA to mandate federal agencies to apply mitigations by July 16, 2026. The resurgence of exploitation of this 17-year-old vulnerability underscores the persistent risk posed by unpatched legacy systems. Organizations are urged to reassess their network infrastructure, prioritize the remediation of known vulnerabilities, and implement robust patch management practices to mitigate potential threats.
6 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports