✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
NVIDIA GeForce NOW Data Breach in Armenia: What You Need to Know
In early May 2026, NVIDIA confirmed a data breach affecting its GeForce NOW service in Armenia, managed by regional partner GFN.am. The breach, occurring between March 20 and 26, exposed user data including full names, email addresses, phone numbers, dates of birth, and usernames. NVIDIA's own infrastructure remained unaffected, and GFN.am has initiated notifications to impacted users. The threat actor, identified as ShinyHunters, claimed responsibility and attempted to sell the stolen data online. This incident underscores the persistent threat posed by cybercriminal groups like ShinyHunters, known for targeting high-profile organizations. It highlights the critical need for robust security measures and vigilant monitoring of third-party partnerships to safeguard user data against sophisticated cyberattacks.
2 months ago
Kill Chain
TCLBANKER: A New Threat to Financial Platforms via WhatsApp and Outlook
In May 2026, Elastic Security Labs identified a new Brazilian banking trojan named TCLBANKER, which targets 59 banking, fintech, and cryptocurrency platforms. The malware is distributed through a trojanized Logitech installer and employs advanced anti-analysis techniques. Once installed, TCLBANKER monitors browser activity and overlays fraudulent interfaces to steal user credentials. Additionally, it propagates via WhatsApp and Outlook by sending malicious links to the victim's contacts, facilitating further infections. This incident underscores the evolving sophistication of banking trojans, particularly in their use of legitimate applications for distribution and self-propagation through popular communication platforms. Organizations must enhance their security measures to detect such advanced threats and educate users on recognizing and avoiding malicious links.
2 months ago
Kill Chain
CallPhantom Scam: Unveiling the Deception of Fake Call History Apps
In May 2026, cybersecurity researchers uncovered a fraudulent campaign involving 28 Android applications, collectively known as 'CallPhantom,' on the Google Play Store. These apps falsely claimed to provide access to call histories, SMS records, and WhatsApp call logs for any phone number. Users were prompted to pay subscription fees, ranging from €5 to $80, only to receive randomly generated data instead of the promised information. The apps amassed over 7.3 million downloads before being removed from the store. ([eset.com](https://www.eset.com/us/about/newsroom/research/eset-research-callphantom-scam-google-play/?utm_source=openai)) This incident highlights the persistent threat of deceptive applications infiltrating official app stores, exploiting user trust, and causing financial harm. It underscores the necessity for continuous vigilance, robust app vetting processes, and user education to mitigate the risks associated with such fraudulent schemes.
2 months ago
Kill Chain
Critical 'Dirty Frag' Vulnerability in Linux Kernel Grants Root Access
A critical local privilege escalation (LPE) vulnerability, dubbed 'Dirty Frag,' has been identified in the Linux kernel, affecting major distributions such as Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16. This flaw allows unprivileged local users to gain root access by exploiting a logic error in the kernel's cryptographic module. The vulnerability has been actively exploited in the wild, with a publicly available proof-of-concept demonstrating its reliability across affected systems. Immediate patching is essential to mitigate the risk of unauthorized system control. The disclosure of 'Dirty Frag' underscores the persistent challenges in securing widely used open-source software. Organizations must prioritize timely updates and consider implementing additional security measures, such as disabling vulnerable modules or restricting access, to protect against potential exploits targeting this and similar vulnerabilities.
2 months ago
Kill Chain
Dirty Frag: Unpatched Linux Vulnerability Grants Root Access
On May 7, 2026, a critical Linux kernel vulnerability known as 'Dirty Frag' was publicly disclosed. This flaw allows unprivileged local users to escalate their privileges to root across major Linux distributions, including Ubuntu, RHEL, Fedora, and others. Discovered by security researcher Hyunwoo Kim, Dirty Frag exploits two distinct vulnerabilities within the IPsec ESP and RxRPC modules, enabling attackers to modify read-only files in the page cache, leading to full system compromise. The premature disclosure occurred before patches were available, leaving systems vulnerable without immediate remediation options. The urgency of addressing Dirty Frag is heightened by its similarity to the recently disclosed 'Copy Fail' vulnerability (CVE-2026-31431), which also facilitates local privilege escalation. The public availability of exploit code for both vulnerabilities increases the risk of widespread exploitation. Organizations must prioritize mitigating these vulnerabilities to prevent potential system compromises and data breaches.
2 months ago
Kill Chain
CallPhantom Scam: Deceptive Android Apps Exploit User Curiosity
In November 2025, ESET researchers identified a series of fraudulent Android applications, collectively named 'CallPhantom,' on the Google Play Store. These 28 apps falsely claimed to provide access to call logs, SMS records, and WhatsApp call histories for any phone number. Users were prompted to pay for these services but received only randomly generated, fabricated data. The apps amassed over 7.3 million downloads before being reported to Google and subsequently removed from the store. This incident underscores the persistent threat of deceptive applications exploiting user curiosity and trust. The CallPhantom scam highlights the need for continuous vigilance against fraudulent apps, especially as cybercriminals increasingly target mobile platforms. Users should be cautious of apps requesting payments for services that seem too good to be true and verify the legitimacy of applications before installation.
2 months ago
Kill Chain
TCLBanker: The Self-Spreading Banking Trojan Threatening Financial Security
In May 2026, a sophisticated banking trojan named TCLBanker emerged, targeting 59 banking, fintech, and cryptocurrency platforms primarily in Brazil. The malware infiltrates systems through a trojanized MSI installer for Logitech AI Prompt Builder, employing DLL side-loading to evade detection. Once installed, TCLBanker monitors browser activity, activating when users access targeted financial websites. It establishes a WebSocket connection to its command-and-control server, enabling attackers to perform live screen streaming, keylogging, clipboard hijacking, and remote command execution. Additionally, TCLBanker features self-propagating worm modules that exploit WhatsApp and Outlook to spread the malware to the victim's contacts, significantly increasing its reach and impact. The emergence of TCLBanker underscores a concerning evolution in banking malware, combining advanced evasion techniques with self-propagation capabilities. This development highlights the urgent need for enhanced cybersecurity measures, particularly in the financial sector, to counteract increasingly sophisticated threats that can rapidly disseminate through trusted communication channels.
2 months ago
Kill Chain
Exploitation of PAN-OS Captive Portal Zero-Day (CVE-2026-0300) for Unauthenticated Remote Code Execution
On May 6, 2026, Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow vulnerability in the User-ID™ Authentication Portal (Captive Portal) service of PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Limited exploitation has been observed, with attackers deploying tools like EarthWorm and ReverseSocks5, conducting Active Directory enumeration, and systematically erasing logs to conceal their activities. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=openai)) This incident underscores the escalating trend of state-sponsored actors targeting edge-network devices to gain privileged access. The use of publicly available tools and meticulous operational tactics highlights the need for organizations to secure their network perimeters and implement robust monitoring to detect and mitigate such sophisticated threats. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=openai))
2 months ago
Kill Chain
Critical Palo Alto PAN-OS Zero-Day CVE-2026-0300 Under Active Exploitation
In early May 2026, Palo Alto Networks disclosed a critical zero-day vulnerability (CVE-2026-0300) in its PAN-OS software, specifically affecting the User-ID Authentication Portal service. This buffer overflow flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Active exploitation of this vulnerability has been observed, particularly targeting firewalls with the User-ID Authentication Portal exposed to untrusted networks or the public internet. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai)) The urgency of this situation is heightened by the vulnerability's high CVSS score of 9.3 and the low complexity required for exploitation. With over 5,800 publicly exposed VM-Series firewalls running PAN-OS identified, the potential for widespread impact is significant. Organizations are advised to implement Palo Alto Networks' mitigation strategies immediately and apply patches as soon as they become available.
2 months ago
Kill Chain
xlabs_v1 Botnet: A New Threat Exploiting ADB-Exposed IoT Devices
In May 2026, cybersecurity researchers uncovered a new botnet named xlabs_v1, derived from the Mirai malware, which exploits internet-exposed devices running Android Debug Bridge (ADB) on TCP port 5555. This botnet targets devices such as Android TV boxes, set-top boxes, and smart TVs, enlisting them to perform distributed denial-of-service (DDoS) attacks, particularly against game servers and Minecraft hosts. The malware supports 21 flood variants across TCP, UDP, and raw protocols, including RakNet and OpenVPN-shaped UDP, capable of bypassing consumer-grade DDoS protection. Notably, xlabs_v1 lacks a persistence mechanism, requiring re-infection for each attack, and includes a 'killer' subsystem to eliminate competing malware, ensuring full control over the compromised device's bandwidth. ([thehackernews.com](https://thehackernews.com/2026/05/mirai-based-xlabsv1-botnet-exploits-adb.html?utm_source=openai)) The emergence of xlabs_v1 highlights the ongoing evolution of IoT-targeted malware and the increasing sophistication of DDoS-for-hire services. This incident underscores the critical need for securing IoT devices, particularly those with default-enabled services like ADB, to prevent their exploitation in large-scale cyber attacks.
2 months ago
Kill Chain
Rockstar Games Data Breach: A Case Study in Third-Party Exploitation
In April 2026, Rockstar Games experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers exploited vulnerabilities in Anodot, a monitoring tool integrated with Rockstar's Snowflake cloud infrastructure, to gain unauthorized access. This breach led to the exfiltration of nearly 80 million records, including sensitive internal corporate information. While Rockstar confirmed that no player data or passwords were compromised, the incident underscores the risks associated with third-party integrations and the potential for indirect attack vectors. This breach is part of a broader trend of financially motivated cyber extortion campaigns targeting major organizations. ShinyHunters' tactics, particularly their use of social engineering and exploitation of third-party services, highlight the evolving threat landscape. Organizations must remain vigilant, ensuring robust security measures are in place for both internal systems and external partnerships to mitigate such risks.
2 months ago
Kill Chain
Unveiling Threat Activity Enablers: Key Players in 2025's Cyber Threat Landscape
In 2025, Recorded Future's Insikt Group identified a significant rise in the utilization of Threat Activity Enablers (TAEs)—entities that provide infrastructure and services to support malicious cyber activities. These TAEs, often operating through complex networks of shell companies and lacking stringent Know Your Customer (KYC) policies, have become central to the operations of ransomware groups, botnets, and state-sponsored actors. Notably, German hosting provider aurologic GmbH emerged as a key player, offering services to multiple high-risk networks implicated in various cyber threats. ([recordedfuture.com](https://www.recordedfuture.com/research/malicious-infrastructure-finds-stability-with-aurologic-gmbh?utm_source=openai)) The persistence and adaptability of TAEs pose a substantial challenge to cybersecurity efforts. Their ability to rapidly rebrand and manipulate network resources allows them to evade sanctions and takedowns, ensuring the continuity of malicious operations. This trend underscores the necessity for organizations to enhance their threat intelligence capabilities and adopt proactive measures to identify and mitigate risks associated with such enablers. ([recordedfuture.com](https://www.recordedfuture.com/blog/threat-activity-enablers?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports