✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
UNC5221's Prolonged Cyber-Espionage via Brickstorm Malware
In June 2026, the Chinese state-sponsored group UNC5221, also known as VerdantBamboo, was found to have infiltrated U.S. organizations using the Brickstorm backdoor and newly identified malware variants, Plenet and AgentPSD. The attackers maintained undetected access for over 18 months, compromising Microsoft 365 environments and managed service providers. Their tactics included exploiting zero-day vulnerabilities in edge devices and deploying advanced malware implants written in Golang and Rust. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks/amp/?utm_source=openai)) This incident underscores the evolving sophistication of state-sponsored cyber-espionage campaigns, highlighting the need for organizations to enhance their detection capabilities, particularly in monitoring network appliances and implementing robust access controls to prevent prolonged unauthorized access.
1 month ago
Kill Chain
Asin Spyware: A New Threat to Arabic-Speaking Android Users
In early 2025, a sophisticated cyber espionage campaign emerged targeting Arabic-speaking Android users. The threat actor, identified as Arid Viper (also known as APT-C-23, Desert Falcon, or TAG-63), distributed a new spyware variant named Asin through deceptive applications. These malicious apps masqueraded as legitimate utilities, war-related updates, and government news sources, enticing users to download them. Once installed, Asin granted attackers extensive access to victims' devices, enabling the collection of sensitive information such as contacts, messages, and location data. The campaign's strategic use of culturally relevant themes and trusted app appearances significantly increased its effectiveness, leading to widespread data exfiltration and potential national security implications. This incident underscores a growing trend in cyber threats where attackers exploit regional conflicts and cultural contexts to enhance the credibility of their malicious campaigns. The use of sophisticated social engineering tactics, combined with the targeting of specific linguistic and cultural groups, highlights the evolving nature of cyber espionage. Organizations and individuals must remain vigilant, especially in regions experiencing geopolitical tensions, as such environments are increasingly exploited by threat actors to conduct targeted attacks.
1 month ago
Kill Chain
Critical Authentication Bypass Vulnerability in Palo Alto Networks PAN-OS (CVE-2026-0257)
In May 2026, a critical authentication bypass vulnerability (CVE-2026-0257) was discovered in Palo Alto Networks' PAN-OS software, specifically affecting the GlobalProtect portal and gateway components. This flaw allowed remote, unauthenticated attackers to establish unauthorized VPN connections, potentially exposing internal networks to malicious access. Rapid7's Managed Detection and Response team observed active exploitation of this vulnerability starting on May 17, 2026, leading to its inclusion in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog. Palo Alto Networks released security patches beginning May 15, 2026, urging immediate updates to mitigate the risk. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0257?utm_source=openai)) The exploitation of CVE-2026-0257 underscores the critical importance of timely vulnerability management and patch application. Organizations relying on PAN-OS for secure remote access must ensure their systems are updated to prevent unauthorized access and potential data breaches. This incident highlights the ongoing challenges in securing network infrastructure against rapidly evolving threats.
1 month ago
Kill Chain
Critical SSRF Vulnerability in Cisco Unified CM: CVE-2026-20230
In June 2026, Cisco disclosed a critical server-side request forgery (SSRF) vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM) and Unified CM Session Management Edition. This flaw allows unauthenticated remote attackers to send crafted HTTP requests, enabling them to write files to the underlying operating system and potentially escalate privileges to root. The vulnerability specifically affects systems with the WebDialer service enabled, which is disabled by default. Cisco has released security updates to address this issue and recommends administrators either apply the patches or disable the WebDialer service to mitigate the risk. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cucm-ssrf-cXPnHcW.html?utm_source=openai)) The rapid public availability of proof-of-concept exploit code for CVE-2026-20230 underscores the urgency for organizations to address this vulnerability promptly. Given the critical nature of the flaw and the potential for privilege escalation, it is imperative for enterprises using Cisco Unified CM to assess their exposure and implement the recommended mitigations without delay. ([techtimes.com](https://www.techtimes.com/articles/317782/20260604/cisco-unified-cm-ssrf-flaw-cve-2026-20230-public-exploit-code-opens-path-root.htm?utm_source=openai))
1 month ago
Kill Chain
Critical Cisco Unified CM Vulnerability CVE-2026-20230: Public Exploit Code Released
In June 2026, Cisco disclosed a critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-20230, in its Unified Communications Manager (Unified CM) and Unified CM Session Management Edition. This flaw allows unauthenticated, remote attackers to send crafted HTTP requests, enabling them to write files to the underlying operating system and potentially escalate privileges to root. The vulnerability resides in the WebDialer service, which is disabled by default. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cucm-ssrf-cXPnHcW.html?utm_source=openai)) The public release of proof-of-concept exploit code has heightened the urgency for organizations to address this vulnerability promptly. Given the critical nature of Unified CM in enterprise telephony infrastructure, successful exploitation could lead to significant operational disruptions and unauthorized access to sensitive communications. ([techtimes.com](https://www.techtimes.com/articles/317782/20260604/cisco-unified-cm-ssrf-flaw-cve-2026-20230-public-exploit-code-opens-path-root.htm?utm_source=openai))
1 month ago
Kill Chain
Cybersecurity Challenges Facing the 2026 FIFA World Cup
As the 2026 FIFA World Cup approaches, cybercriminals are intensifying efforts to exploit the event's global prominence. Recent reports indicate a surge in phishing campaigns, with over 4,300 fraudulent domains mimicking FIFA's official website to deceive fans into providing personal and financial information. Additionally, state-sponsored actors are anticipated to target tournament infrastructure, aiming to disrupt operations and gather intelligence. These activities pose significant risks to fans, organizations, and the integrity of the event. The current landscape underscores the evolving nature of cyber threats associated with major global events. The proliferation of AI-generated content and deepfake technologies has enabled more sophisticated phishing and social engineering attacks. Organizations involved in the World Cup must enhance their cybersecurity measures to mitigate these risks and protect stakeholders from potential breaches and fraud.
1 month ago
Kill Chain
SideCopy's Xeno RAT Attack on Afghan Finance Ministry: A Case Study
In May 2025, the Pakistan-linked APT group SideCopy initiated a cyberespionage campaign targeting Afghanistan's Ministry of Finance and provincial finance offices. The attackers employed spear-phishing emails containing ZIP archives with malicious LNK files disguised as PDFs. These files, when executed, utilized mshta.exe to fetch an HTA payload from a compromised Afghan education domain, leading to the deployment of Xeno RAT 1.8.7. This malware enabled remote command execution, data exfiltration, and system monitoring, including keystroke logging and screenshot capture. The campaign demonstrated a deliberate approach to defense evasion by leveraging Pashto-language lures and hosting payloads on Afghan government infrastructure to blend malicious traffic with legitimate state communications. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/pakistan-spies-afghan-finance-ministry-xeno-rat?utm_source=openai)) This incident underscores the persistent threat posed by nation-state actors employing sophisticated social engineering tactics and leveraging local infrastructure to conduct espionage. Organizations, especially governmental entities, must enhance their cybersecurity posture by implementing robust email filtering, user education on phishing threats, and continuous monitoring for indicators of compromise to mitigate such risks.
1 month ago
Kill Chain
TA4922's Global Expansion: A New Cyber Threat Landscape
In early 2026, the China-linked cybercrime group TA4922 expanded its operations beyond East Asia, targeting organizations in the U.K., Germany, Italy, and South Africa. The group employed sophisticated phishing campaigns using localized lures related to tax filings, payroll, and compliance to deliver malware such as ValleyRAT (Winos 4.0), Atlas RAT, RomulusLoader, and SilentRunLoader. These attacks aimed to gain unauthorized access for data theft, fraud, and persistent access. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global?utm_source=openai)) This incident underscores the evolving threat landscape, where financially motivated cybercriminals are rapidly adapting their tactics and expanding their reach globally. Organizations must remain vigilant against such sophisticated phishing campaigns and enhance their cybersecurity measures to mitigate these risks.
1 month ago
Kill Chain
Europol's Operation Kratos 2: A Major Blow to Digital Piracy
Between September 2025 and April 2026, European authorities conducted Operation Kratos 2, a coordinated effort led by Bulgaria and supported by Europol, targeting illegal streaming networks. This seven-month operation resulted in 29 arrests, the dismantling of nine organized crime groups, and the removal of over 27,000 illegal streaming URLs that infringed on nearly 850,000 media assets across 169 domains. The operation also involved 148 house searches, identification of 86 suspects, and referral of 59 cases for criminal proceedings. Investigators collaborated with private-sector partners to identify nearly 4,400 new domains and more than 18,000 IP addresses linked to piracy and other illegal activities, leading to the reporting of almost 400,000 additional URLs for suspension or removal. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/29-arrested-law-enforcement-strikes-criminal-networks-behind-illegal-streaming?utm_source=openai)) This operation underscores the persistent threat posed by sophisticated criminal enterprises exploiting digital platforms for illegal content distribution. The success of Operation Kratos 2 highlights the importance of international collaboration in combating digital piracy and protecting intellectual property rights.
1 month ago
Kill Chain
Critical Vulnerabilities in Acer Wave 7 Routers: CVE-2026-49200 and CVE-2026-49201
In May 2026, security researcher Gergo Pap identified two critical vulnerabilities in Acer's Wave 7 mesh routers running firmware version T7c_GBL_1.01.000055 or earlier. The first vulnerability (CVE-2026-49200) allows unauthenticated remote access to the 'acer_cgi.log' file via the web interface, exposing cleartext login credentials and enabling unauthorized system access. The second vulnerability (CVE-2026-49201) involves a hardcoded AES encryption key in the 'upload.cgi' binary, permitting attackers to decrypt, modify, and re-encrypt system backups, potentially injecting persistent backdoors into the router. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/?utm_source=openai)) These vulnerabilities underscore the critical importance of securing network infrastructure devices, as they can serve as entry points for attackers to infiltrate organizational networks. The incident highlights the necessity for manufacturers to implement robust security measures, including proper access controls and secure cryptographic practices, to prevent such exposures.
1 month ago
Kill Chain
CISA Alerts on Active Exploitation of Android and Linux Vulnerabilities
In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-48595 and CVE-2022-0492. CVE-2025-48595 is a high-severity integer overflow vulnerability in the Android Framework affecting versions 14 through 16, allowing local privilege escalation without user interaction. CVE-2022-0492 is a privilege escalation flaw in the Linux kernel's cgroups v1 subsystem, enabling attackers to bypass namespace isolation and potentially gain root access on host systems. Both vulnerabilities have been actively exploited in the wild, prompting immediate patching and mitigation efforts. The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by privilege escalation flaws in widely used operating systems. Organizations are urged to prioritize the application of security updates to mitigate potential exploitation risks and protect their systems from unauthorized access and control.
1 month ago
Kill Chain
Exploiting Google Gemini: The Rise of Prompt Injection Attacks
In June 2026, a security vulnerability was discovered in Google Gemini's voice assistant, allowing attackers to exploit its notification summarization feature through prompt injection techniques. By embedding malicious commands within message notifications, adversaries could manipulate the assistant to perform unauthorized actions such as controlling smart home devices, initiating video streams, conducting social engineering attacks, and compromising the integrity of large language model (LLM) memory. This flaw was identified and responsibly disclosed by SafeBreach, leading Google to implement content classifier updates to mitigate the issue. This incident underscores the evolving threat landscape associated with AI-powered assistants and the critical need for robust security measures to prevent prompt injection attacks. As AI integration in daily applications increases, ensuring the integrity and security of these systems becomes paramount to protect users from sophisticated exploitation methods.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports