The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

943 threat reports
Page 1 of 79

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Telecommunications Threat Reports

Showing 1–12 / 943 reports
MacSync Malware Weaponizes iCloud Calendars in Advanced macOS Attack Campaign
Impact· HIGH

MacSync Malware Weaponizes iCloud Calendars in Advanced macOS Attack Campaign

MacSync, a Swift-based infostealer malware targeting macOS systems, has evolved to use public iCloud calendar events as a novel command and control mechanism to deliver fresh payloads. First emerging in April 2025 and derived from the AMOS stealer family, MacSync has been distributed through social engineering campaigns including ClickFix attacks, fake applications, and fraudulent crypto wallets. The malware's latest iteration includes a new Objective-C backdoor module that disguises itself as Finder and establishes persistence through LaunchAgent modifications, targeting browser credentials, crypto wallets, SSH configurations, and system information while evading detection by terminating macOS notification processes. This incident highlights the growing sophistication of macOS-targeted malware as attackers increasingly focus on Apple's ecosystem, exploiting trusted cloud services like iCloud for command and control operations while incorporating advanced evasion techniques that bypass traditional security controls.

10 minutes ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical OnePlus Privilege Escalation Flaws Leave Millions of Devices Vulnerable to Root Access
Impact· HIGH

Critical OnePlus Privilege Escalation Flaws Leave Millions of Devices Vulnerable to Root Access

In September 2026, security researcher Rasmus Moorats disclosed two unpatched vulnerabilities in OnePlus devices that allow malicious Android applications to gain root access without requesting any permissions. The attack chains two flaws: one in OnePlus's AtlasService debugging component that accepts unchecked calls from any app, and another in the olc2 hardware helper service that executes arbitrary shell commands. The vulnerabilities affect OnePlus 15, OnePlus 12 Pro, and potentially all devices running OxygenOS 16, as well as OPPO devices due to shared codebase. OnePlus acknowledged the flaws in May 2026 but threatened legal action against disclosure and has not released patches as of the researcher's September publication. This incident highlights the growing trend of privilege escalation vulnerabilities in Android OEM customizations, following similar discoveries across Samsung, Xiaomi, and other manufacturers in 2026, demonstrating systemic security gaps in vendor-modified Android implementations.

46 minutes ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Russian Hybrid Warfare Escalates Across Europe: The New Generation Warfare Threat
Impact· HIGH

Russian Hybrid Warfare Escalates Across Europe: The New Generation Warfare Threat

Since February 2022, Russia has significantly escalated hybrid warfare operations across Europe as part of its New Generation Warfare (NGW) strategy, extending far beyond traditional Soviet territories. Russian state-sponsored groups have conducted coordinated cyber and physical sabotage campaigns targeting critical infrastructure, government entities, and private sector organizations throughout European nations. These operations have resulted in widespread disruption of services, data breaches, and potential threats to personnel safety across multiple sectors including energy, telecommunications, and transportation. This escalation represents a critical shift in modern threat landscapes as nation-state actors increasingly blur the lines between cyber warfare and physical attacks, making hybrid threats one of the most pressing security challenges facing organizations today.

1 hour ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Corp MDM Android Spyware Campaign Exposes Critical Mobile Security Gaps in Logistics Sector
Impact· HIGH

Corp MDM Android Spyware Campaign Exposes Critical Mobile Security Gaps in Logistics Sector

In September 2026, a sophisticated Android spyware campaign dubbed Corp MDM targeted logistics firms including CEVA and TKW Logistics through fake Google Play Store pages. The malware, distributed via fraudulent APK files disguised as system services, enabled attackers to intercept SMS messages, redirect calls, and maintain persistent device access. The campaign utilized cleartext HTTP communications to exfiltrate sensitive data including one-time passwords, transaction notifications, and delivery updates, with command-and-control infrastructure hosted at IP address 69.55.61.82. The operation appears to be orchestrated by Russian-Armenian threat actors and represents part of a broader multi-platform assault on the logistics sector involving credential phishing and Windows-based malware. This incident highlights the escalating sophistication of mobile-targeted supply chain attacks as threat actors increasingly weaponize AI-assisted development and exploit the logistics sector's heavy reliance on mobile communications for operational coordination.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salt Typhoon Attack Exposes Critical Telecom Vulnerabilities, Drives Senate Cybersecurity Action
Impact· HIGH

Salt Typhoon Attack Exposes Critical Telecom Vulnerabilities, Drives Senate Cybersecurity Action

The Salt Typhoon campaign represents one of the most significant nation-state espionage operations against U.S. telecommunications infrastructure, attributed to Chinese threat actors who infiltrated major telecom carriers including Verizon, AT&T, and T-Mobile. Beginning in 2022 and persisting through 2024, the attackers gained deep access to telecommunications networks, intercepting communications from high-profile political figures including presidential candidates, and accessing sensitive customer data and call records. The breach exposed critical vulnerabilities in telecom infrastructure security and prompted bipartisan legislative action to establish mandatory cybersecurity standards for the telecommunications sector. This incident highlights the urgent need for Zero Trust network segmentation and encrypted communications as nation-state actors increasingly target critical infrastructure. The persistence and scope of Salt Typhoon demonstrate how traditional perimeter-based security models fail against sophisticated adversaries who can maintain long-term access to compromise sensitive communications and national security information.

8 hours ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Zero-Day in Arista VeloCloud Orchestrator Exposes SD-WAN Infrastructure Risk
Impact· CRITICAL

Critical Zero-Day in Arista VeloCloud Orchestrator Exposes SD-WAN Infrastructure Risk

In September 2026, Arista Networks disclosed CVE-2026-93952, a maximum-severity zero-day vulnerability in VeloCloud Orchestrator (VCO) On-Prem deployments that was being actively exploited. The flaw stems from improper input validation in certificate-based authentication, allowing remote attackers to access privileged internal VCO host functionality without requiring system privileges or user interaction. The U.S. CISA immediately added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies secure their networks within 48 hours. This incident highlights the escalating threat to SD-WAN infrastructure as organizations increasingly rely on hybrid connectivity solutions. With Arista being a Fortune 500 company serving over 10,000 customers worldwide, this zero-day demonstrates how critical network infrastructure remains a high-value target for sophisticated threat actors seeking to compromise enterprise connectivity and potentially pivot to broader network access.

23 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
September 2026: State-Sponsored Groups Target Network Management Infrastructure
Impact· CRITICAL

September 2026: State-Sponsored Groups Target Network Management Infrastructure

The September 2026 InfraTrust Pulse report revealed a concerning escalation in attacks targeting network infrastructure management systems, with 158 security advisories covering 1,699 vulnerabilities across 17 vendors. Attackers successfully exploited critical flaws in Cisco Secure Firewall Management Center (CVE-2026-20079), Cisco Identity Services Engine (CVE-2026-76460), and SonicWall SMA 1000 appliances before vendors could patch them. State-sponsored groups including Sandworm and ransomware gangs like Qilin chained these vulnerabilities to gain root access, deploy tunneling tools, harvest credentials, and establish persistent control over enterprise network infrastructure. This incident represents a strategic shift where threat actors are bypassing individual network devices to compromise the centralized management platforms that control entire network fabrics, amplifying their impact across organizations' critical infrastructure.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
RemControl Android Banking Malware: New MaaS Platform Targets Europe and Canada
Impact· HIGH

RemControl Android Banking Malware: New MaaS Platform Targets Europe and Canada

In September 2026, cybersecurity researchers discovered RemControl, a new Android malware-as-a-service (MaaS) platform targeting banking users across Europe and Canada through sophisticated phishing campaigns. The malware impersonates the popular TVTap IPTV application via fake Google Play pages and malvertising campaigns, deploying over 30 banking overlays to steal credentials from financial institutions across Italy, France, Spain, Poland, Portugal, and Canada. RemControl employs advanced evasion techniques including VPN services to block Google Play Protect scans, accessibility service abuse for remote device control, and dynamic C2 infrastructure rotation via Telegram channels. This incident highlights the continued evolution of mobile banking trojans, particularly the integration of AI-assisted development and sophisticated anti-detection mechanisms. The malware's ability to dynamically receive new targets and perform real-time device manipulation represents a significant escalation in mobile banking threats, coinciding with increased regulatory focus on mobile security frameworks.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
MikroTrick Vulnerability Chain Compromises MikroTik Routers Without Authentication
Impact· HIGH

MikroTrick Vulnerability Chain Compromises MikroTik Routers Without Authentication

In September 2026, attackers exploited the MikroTrick vulnerability chain (CVE-2026-67279 and CVE-2026-86060) to gain full administrative control of internet-exposed MikroTik routers without passwords or SSH keys. The attack combined an SSH state-machine flaw that bypassed authentication with an argument-injection vulnerability in RouterOS login process. Evidence shows active exploitation began September 2, 2026, one day before patches were released, with attackers creating privileged accounts and exfiltrating configuration data from compromised devices. This incident highlights the growing threat to network infrastructure devices as nation-state actors and cybercriminals increasingly target routers and edge devices for persistent access and lateral movement capabilities.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Gulf Cyber Crisis: UAE and Saudi Arabia Under AI-Powered Attack Siege
Impact· HIGH

Gulf Cyber Crisis: UAE and Saudi Arabia Under AI-Powered Attack Siege

The United Arab Emirates and Saudi Arabia absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026, with organizations experiencing nearly 2,700 attacks per week compared to the global average of 2,300. The attacks have shifted from highly visible DDoS and website defacements to sophisticated, targeted intrusions focusing on vulnerability exploitation (38% of initial access vectors), stealthy infiltration of critical infrastructure, and data gathering operations. These financially-motivated cybercriminals are leveraging AI tools to accelerate exploit development and target the expanded attack surfaces created by aggressive digital transformation initiatives in both nations. This incident reflects the broader evolution of cyber threats in 2026, where AI-assisted attackers are demonstrating near-autonomous capabilities that can progress faster than traditional defense mechanisms. The emergence of autonomous sandbox breakouts and AI-accelerated vulnerability discovery represents a fundamental shift in the threat landscape, forcing organizations to rethink their cybersecurity strategies beyond conventional perimeter defenses.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Adds Four Critical Vulnerabilities to KEV Catalog Under New BOD 26-04 Requirements
Impact· CRITICAL

CISA Adds Four Critical Vulnerabilities to KEV Catalog Under New BOD 26-04 Requirements

On September 22, 2026, CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after detecting active exploitation in the wild. The vulnerabilities span Check Point security appliances (CVE-2026-85102, CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), and F5 BIG-IP APM systems (CVE-2026-94127), affecting certificate validation, path traversal, input validation, and buffer overflow protections. These flaws enable attackers to achieve remote code execution and gain total system control on publicly exposed enterprise infrastructure. The addition coincides with the enforcement of Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of KEV-listed vulnerabilities on internet-facing assets while establishing new requirements for compromise assessments prior to patching.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Chinese Threat Actors Exploit Zyxel Switch Flaw to Steal Government Data
Impact· HIGH

Chinese Threat Actors Exploit Zyxel Switch Flaw to Steal Government Data

In September 2026, CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog after Chinese-speaking threat actors exploited a stack-based buffer overflow in Zyxel GS1900 series switches. The vulnerability allows unauthenticated attackers to execute OS commands via malicious HTTP requests. GreyNoise reported that attackers successfully compromised nearly 1,000 switches across 48 countries, exfiltrating sensitive data. CISA ordered federal agencies to patch by Thursday under BOD 26-04. This incident highlights the ongoing risk to network infrastructure devices that often lack proper security monitoring and timely patching. As threat actors increasingly target edge devices for initial access and data exfiltration, organizations must prioritize vulnerability management for network equipment beyond traditional endpoints and servers.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports